CVE-2014-8630
Summary
| CVE | CVE-2014-8630 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-02-01 15:59:00 UTC |
| Updated | 2017-01-03 02:59:00 UTC |
| Description | Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name. |
Risk And Classification
Problem Types: CWE-77
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 20 | All | All | All |
| Operating System | Fedoraproject | Fedora | 21 | All | All | All |
| Operating System | Fedoraproject | Fedora | 20 | All | All | All |
| Operating System | Fedoraproject | Fedora | 21 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2 | rc1 | All | All |
| Application | Mozilla | Bugzilla | 4.2 | rc2 | All | All |
| Application | Mozilla | Bugzilla | 4.2.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.10 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.11 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.6 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.7 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.8 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.9 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4 | rc1 | All | All |
| Application | Mozilla | Bugzilla | 4.4 | rc2 | All | All |
| Application | Mozilla | Bugzilla | 4.4.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.6 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.6 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2 | rc1 | All | All |
| Application | Mozilla | Bugzilla | 4.2 | rc2 | All | All |
| Application | Mozilla | Bugzilla | 4.2.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.10 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.11 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.6 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.7 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.8 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.9 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4 | rc1 | All | All |
| Application | Mozilla | Bugzilla | 4.4 | rc2 | All | All |
| Application | Mozilla | Bugzilla | 4.4.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.6 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.6 | All | All | All |
| Application | Mozilla | Bugzilla | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mageia Advisory: MGASA-2015-0048 - Updated bugzilla packages fix CVE-2014-8630 | CONFIRM | advisories.mageia.org | |
| www.mandriva.com | MANDRIVA | www.mandriva.com | |
| [SECURITY] Fedora 20 Update: bugzilla-4.2.13-1.fc20 | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| [SECURITY] Fedora 21 Update: bugzilla-4.4.8-1.fc21.1 | FEDORA | lists.fedoraproject.org | Third Party Advisory |
| 5.0rc1, 4.4.6, 4.2.11, and 4.0.15 Security Advisory :: Bugzilla :: bugzilla.org | CONFIRM | www.bugzilla.org | Issue Tracking, Patch, Vendor Advisory |
| 1079065 – (CVE-2014-8630) [SECURITY] Always use the 3 arguments form for open() to prevent shell code injection | CONFIRM | bugzilla.mozilla.org | Issue Tracking, Vendor Advisory |
| Bugzilla: Multiple vulnerabilities (GLSA 201607-11) — Gentoo security | GENTOO | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.