Lucene search

K
freebsdFreeBSDC8C927E5-2891-11E0-8F26-00151735203A
HistoryJan 24, 2011 - 12:00 a.m.

bugzilla -- multiple serious vulnerabilities

2011-01-2400:00:00
vuxml.freebsd.org
22

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.065

Percentile

93.9%

A Bugzilla Security Advisory reports:

This advisory covers three security issues that have recently been
fixed in the Bugzilla code:

A weakness in Bugzilla could allow a user to gain unauthorized
access to another Bugzilla account.
A weakness in the Perl CGI.pm module allows injecting HTTP
headers and content to users via several pages in Bugzilla.
If you put a harmful “javascript:” or “data:” URL into
Bugzilla’s “URL” field, then there are multiple situations in
which Bugzilla will unintentionally make that link clickable.
Various pages lack protection against cross-site request
forgeries.

All affected installations are encouraged to upgrade as soon as
possible.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchbugzilla= 2.14.*UNKNOWN
FreeBSDanynoarchbugzilla< 3.6.4UNKNOWN

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

EPSS

0.065

Percentile

93.9%