PT-2004-1221 · Mozilla · Bugzilla

Stefan Mayr

·

Publicado

2004-06-03

·

Atualizado

2017-07-11

·

CVE-2003-1044

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bugzilla versions 2.16.3 and earlier
Description The issue arises in editproducts.cgi when usebuggroups is enabled. It fails to properly remove group add privileges from a group that is being deleted. This allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID.
Recommendations For Bugzilla versions 2.16.3 and earlier, update to a version where this issue is resolved to prevent unauthorized group additions.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-1044

Produtos afetados

Bugzilla