PT-2003-1310 · Mozilla · Bugzilla

David Miller

·

Published

2003-01-17

·

Updated

2016-10-18

·

CVE-2003-0012

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bugzilla versions 2.14.x through 2.14.4 Bugzilla versions 2.16.x through 2.16.1 Bugzilla versions 2.17.x through 2.17.2
Description The issue allows local users to modify or delete data due to world-writable permissions being set for the data/mining directory by the data collection script.
Recommendations For versions 2.14.x through 2.14.4, update to version 2.14.5 or later. For versions 2.16.x through 2.16.1, update to version 2.16.2 or later. For versions 2.17.x through 2.17.2, update to version 2.17.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0012
DSA-230

Affected Products

Bugzilla