PT-2015-4064 · Mozilla · Bugzilla

Published

2015-01-31

·

Updated

2017-01-03

·

CVE-2014-8630

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bugzilla versions prior to 4.0.16 Bugzilla versions 4.1.x Bugzilla versions 4.2.x prior to 4.2.12 Bugzilla versions 4.3.x Bugzilla versions 4.4.x prior to 4.4.7 Bugzilla versions 5.x prior to 5.0rc1
Description The issue allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.
Recommendations For Bugzilla versions prior to 4.0.16, update to version 4.0.16 or later. For Bugzilla versions 4.1.x, update to version 4.2.12 or later. For Bugzilla versions 4.2.x prior to 4.2.12, update to version 4.2.12 or later. For Bugzilla versions 4.3.x, update to version 4.4.7 or later. For Bugzilla versions 4.4.x prior to 4.4.7, update to version 4.4.7 or later. For Bugzilla versions 5.x prior to 5.0rc1, update to version 5.0rc1 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-8630
MGASA-2015-0048

Affected Products

Bugzilla