PT-2004-1221 · Mozilla · Bugzilla

Stefan Mayr

·

Published

2004-06-03

·

Updated

2017-07-11

·

CVE-2003-1044

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bugzilla versions 2.16.3 and earlier
Description The issue arises in editproducts.cgi when usebuggroups is enabled. It fails to properly remove group add privileges from a group that is being deleted. This allows users with those privileges to perform unauthorized additions to the next group that is assigned with the original group ID.
Recommendations For Bugzilla versions 2.16.3 and earlier, update to a version where this issue is resolved to prevent unauthorized group additions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1044

Affected Products

Bugzilla