CVE-2014-8630
Summary
| CVE | CVE-2014-8630 |
|---|---|
| State | PUBLISHED |
| Assigner | mozilla |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-02-01 15:59:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fedoraproject | Fedora | 20 | All | All | All |
| Operating System | Fedoraproject | Fedora | 21 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.1.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2 | rc1 | All | All |
| Application | Mozilla | Bugzilla | 4.2 | rc2 | All | All |
| Application | Mozilla | Bugzilla | 4.2.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.10 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.11 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.6 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.7 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.8 | All | All | All |
| Application | Mozilla | Bugzilla | 4.2.9 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.3.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4 | rc1 | All | All |
| Application | Mozilla | Bugzilla | 4.4 | rc2 | All | All |
| Application | Mozilla | Bugzilla | 4.4.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.4.6 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.1 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.2 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.3 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.4 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.5 | All | All | All |
| Application | Mozilla | Bugzilla | 4.5.6 | All | All | All |
| Application | Mozilla | Bugzilla | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 5.0rc1, 4.4.6, 4.2.11, and 4.0.15 Security Advisory :: Bugzilla :: bugzilla.org | af854a3a-2127-422b-91ae-364da2661108 | www.bugzilla.org | Issue Tracking, Patch, Vendor Advisory |
| [SECURITY] Fedora 21 Update: bugzilla-4.4.8-1.fc21.1 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| Mageia Advisory: MGASA-2015-0048 - Updated bugzilla packages fix CVE-2014-8630 | af854a3a-2127-422b-91ae-364da2661108 | advisories.mageia.org | |
| 1079065 – (CVE-2014-8630) [SECURITY] Always use the 3 arguments form for open() to prevent shell code injection | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Issue Tracking, Vendor Advisory |
| www.mandriva.com | af854a3a-2127-422b-91ae-364da2661108 | www.mandriva.com | |
| [SECURITY] Fedora 20 Update: bugzilla-4.2.13-1.fc20 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | Third Party Advisory |
| Bugzilla: Multiple vulnerabilities (GLSA 201607-11) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.