Multiple Mozilla Bugzilla Vulnerabilities
BID:10698
Info
Multiple Mozilla Bugzilla Vulnerabilities
| Bugtraq ID: | 10698 |
| Class: | Unknown |
| CVE: |
CVE-2004-0702 CVE-2004-0703 CVE-2004-0704 CVE-2004-0705 CVE-2004-0706 CVE-2004-0707 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery of these vulnerabilities is credited to, Joel Peshkin <[email protected]>, Felix Hieronymi <[email protected]>, Gabriel Millerd <[email protected]>, Laran Evans <[email protected]>, Jouni Heikniemi <[email protected]>, Dave Mi |
| Vulnerable: |
Mozilla Bugzilla 2.17.7 Mozilla Bugzilla 2.17.6 Mozilla Bugzilla 2.17.5 Mozilla Bugzilla 2.17.4 Mozilla Bugzilla 2.17.3 Mozilla Bugzilla 2.17.1 Mozilla Bugzilla 2.17 Mozilla Bugzilla 2.16.5 Mozilla Bugzilla 2.16.4 Mozilla Bugzilla 2.16.3 Mozilla Bugzilla 2.16.2 Mozilla Bugzilla 2.16.1 Mozilla Bugzilla 2.16 Mozilla Bugzilla 2.14.5 Mozilla Bugzilla 2.14.4 Mozilla Bugzilla 2.14.3 Mozilla Bugzilla 2.14.2 Mozilla Bugzilla 2.14.1 Mozilla Bugzilla 2.14 Mozilla Bugzilla 2.12 Mozilla Bugzilla 2.10 Mozilla Bugzilla 2.8 Mozilla Bugzilla 2.6 Mozilla Bugzilla 2.4 |
| Not Vulnerable: | |
Discussion
Multiple Mozilla Bugzilla Vulnerabilities
Multiple vulnerabilities are reported to exist in the Bugzilla software. The issues include cross-site scripting, SQL injection, privilege escalation, and information disclosure.
An information disclosure vulnerability is reported to affect Bugzilla installations under certain circumstances. It is reported that when the SQL server is halted, and the HTTP server continues to run, a remote attacker may disclosure the database password.
An attacker, may employ the harvested password information to authenticate to the SQL database.
A privilege escalation vulnerability is reported to affect Bugzilla.
A privileged attacker may exploit this vulnerability to gain membership to other Bugzilla groups.
An additional information disclosure vulnerability is reported to affect Bugzilla. It is reported that hidden products may be revealed using vulnerable CGI scripts.
An attacker may employ the vulnerable scripts in order to disclose product listings that are marked as confidential.
Bugzilla is reported prone to multiple cross-site scripting vulnerabilities. These issues exist due to a lack of sanitization performed on user supplied URI data before this data is incorporated into dynamically generated error messages.
These cross-site scripting issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If a user follows the malicious link, the attacker-supplied code executes in the web browser of the victim computer.
An additional information disclosure vulnerability is reported to affect Bugzilla. It is reported that a Bugzilla user's password may be embedded as a part of an image URI, the password may be saved into and be visible in web server or web proxy logs.
An attacker who has access to the web server logs may harvest credentials.
Finally, Bugzilla is reported prone to an SQL injection vulnerability. The issue is due to a failure of the application to properly sanitize user-supplied input.
As a result of this issue a privileged attacker could modify the logic and structure of database queries.
Multiple vulnerabilities are reported to exist in the Bugzilla software. The issues include cross-site scripting, SQL injection, privilege escalation, and information disclosure.
An information disclosure vulnerability is reported to affect Bugzilla installations under certain circumstances. It is reported that when the SQL server is halted, and the HTTP server continues to run, a remote attacker may disclosure the database password.
An attacker, may employ the harvested password information to authenticate to the SQL database.
A privilege escalation vulnerability is reported to affect Bugzilla.
A privileged attacker may exploit this vulnerability to gain membership to other Bugzilla groups.
An additional information disclosure vulnerability is reported to affect Bugzilla. It is reported that hidden products may be revealed using vulnerable CGI scripts.
An attacker may employ the vulnerable scripts in order to disclose product listings that are marked as confidential.
Bugzilla is reported prone to multiple cross-site scripting vulnerabilities. These issues exist due to a lack of sanitization performed on user supplied URI data before this data is incorporated into dynamically generated error messages.
These cross-site scripting issues could permit a remote attacker to create a malicious URI link that includes hostile HTML and script code. If a user follows the malicious link, the attacker-supplied code executes in the web browser of the victim computer.
An additional information disclosure vulnerability is reported to affect Bugzilla. It is reported that a Bugzilla user's password may be embedded as a part of an image URI, the password may be saved into and be visible in web server or web proxy logs.
An attacker who has access to the web server logs may harvest credentials.
Finally, Bugzilla is reported prone to an SQL injection vulnerability. The issue is due to a failure of the application to properly sanitize user-supplied input.
As a result of this issue a privileged attacker could modify the logic and structure of database queries.
Exploit / POC
Multiple Mozilla Bugzilla Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple Mozilla Bugzilla Vulnerabilities
Solution:
The vendor has released versions 2.16.6 and 2.18rc1 to address these issues. Further information can be found in the referenced advisory:
Mozilla Bugzilla 2.10
Mozilla Bugzilla 2.12
Mozilla Bugzilla 2.14
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.14.5
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.16.2
Mozilla Bugzilla 2.16.3
Mozilla Bugzilla 2.16.4
Mozilla Bugzilla 2.16.5
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.4
Mozilla Bugzilla 2.6
Mozilla Bugzilla 2.8
Solution:
The vendor has released versions 2.16.6 and 2.18rc1 to address these issues. Further information can be found in the referenced advisory:
Mozilla Bugzilla 2.10
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.12
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.14
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.14.1
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.14.2
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.14.3
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.14.4
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.14.5
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.16
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.16.1
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.16.2
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.16.3
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.16.4
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.16.5
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.17
-
Mozilla bugzilla-2.18rc1.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18rc1.tar.gz
Mozilla Bugzilla 2.17.1
-
Mozilla bugzilla-2.18rc1.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18rc1.tar.gz
Mozilla Bugzilla 2.17.3
-
Mozilla bugzilla-2.18rc1.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18rc1.tar.gz
Mozilla Bugzilla 2.17.4
-
Mozilla bugzilla-2.18rc1.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18rc1.tar.gz
Mozilla Bugzilla 2.17.5
-
Mozilla bugzilla-2.18rc1.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18rc1.tar.gz
Mozilla Bugzilla 2.17.6
-
Mozilla bugzilla-2.18rc1.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18rc1.tar.gz
Mozilla Bugzilla 2.17.7
-
Mozilla bugzilla-2.18rc1.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18rc1.tar.gz
Mozilla Bugzilla 2.4
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.6
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
Mozilla Bugzilla 2.8
-
Mozilla bugzilla-2.16.6.tar.gz
ftp://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.16.6.tar.gz
References
Multiple Mozilla Bugzilla Vulnerabilities
References:
References:
- 2.16.5, 2.17.7 Security Advisory (Mozilla)
- Browser hangs while performing editusers.cgi - updated users page is shown incom (Felix Hieronymi
) - duplicates.cgi reveals products user doesnt have access to (Gabriel Millerd
) - editusers 'query' parameter should be removed (byron jones (glob)
) - If database is stopped, error message divulges DB password (Joel Peshkin
) - Password exposed in URL to chart image if login required to access a chart (Dave Miller
) - product field on edit-multiple includes products the user doesn't have access to (Laran Evans
) - Url-parameter XSS vulnerability in edit*.cgi (Jouni Heikniemi
) - [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7 (David Miller
)