PT-2002-2178 · Mozilla · Bugzilla

Published

2002-10-28

·

Updated

2016-10-18

·

CVE-2002-1196

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Bugzilla versions 2.14.x through 2.14.3 Bugzilla versions 2.16.x through 2.16.0
Description: The issue arises in the editproducts.cgi script of Bugzilla when the usebuggroups feature is enabled and more than 47 groups are specified. It fails to properly calculate bit values for large numbers due to known features of Perl math, which can set multiple bits. This miscalculation grants extra permissions to users.
Recommendations: For Bugzilla versions 2.14.x through 2.14.3, update to version 2.14.4 or later. For Bugzilla versions 2.16.x through 2.16.0, update to version 2.16.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1196
DSA-173

Affected Products

Bugzilla