CVE-2005-2173
Summary
| CVE | CVE-2005-2173 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-07-08 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Bugzilla | 2.17.1 | All | All | All |
| Application | Mozilla | Bugzilla | 2.17.3 | All | All | All |
| Application | Mozilla | Bugzilla | 2.17.4 | All | All | All |
| Application | Mozilla | Bugzilla | 2.17.5 | All | All | All |
| Application | Mozilla | Bugzilla | 2.17.6 | All | All | All |
| Application | Mozilla | Bugzilla | 2.17.7 | All | All | All |
| Application | Mozilla | Bugzilla | 2.18 | All | All | All |
| Application | Mozilla | Bugzilla | 2.18 | rc1 | All | All |
| Application | Mozilla | Bugzilla | 2.18 | rc2 | All | All |
| Application | Mozilla | Bugzilla | 2.18 | rc3 | All | All |
| Application | Mozilla | Bugzilla | 2.18.1 | All | All | All |
| Application | Mozilla | Bugzilla | 2.19 | All | All | All |
| Application | Mozilla | Bugzilla | 2.19.1 | All | All | All |
| Application | Mozilla | Bugzilla | 2.19.2 | All | All | All |
| Application | Mozilla | Bugzilla | 2.19.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2.18.1 and 2.19.3 Security Advisory :: Bugzilla :: bugzilla.org | af854a3a-2127-422b-91ae-364da2661108 | www.bugzilla.org | Patch, Vendor Advisory |
| Bugzilla Lets Remote Users Modify Flags and May Disclose Private Bug Summaries to Remote Users - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| 293159 – [SECURITY] Anyone can change flags and access bug summaries due to a bad check in Flag::validate() and Flag::modify() | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.