Bugzilla Unauthorized Flag Change Access Validation Vulnerability
BID:14198
Info
Bugzilla Unauthorized Flag Change Access Validation Vulnerability
| Bugtraq ID: | 14198 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-2173 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | The individual or individuals responsible for the discovery of this issue are currently unknown; the vendor disclosed this issue. |
| Vulnerable: |
Mozilla Bugzilla 2.19.3 Mozilla Bugzilla 2.19.2 Mozilla Bugzilla 2.19.1 Mozilla Bugzilla 2.18 rc3 Mozilla Bugzilla 2.18 rc2 Mozilla Bugzilla 2.18 rc1 Mozilla Bugzilla 2.17.7 Mozilla Bugzilla 2.17.6 Mozilla Bugzilla 2.17.5 Mozilla Bugzilla 2.17.4 Mozilla Bugzilla 2.17.3 Mozilla Bugzilla 2.17.1 Gentoo Linux |
| Not Vulnerable: |
Mozilla Bugzilla 2.20 rc1 Mozilla Bugzilla 2.18.2 |
Discussion
Bugzilla Unauthorized Flag Change Access Validation Vulnerability
Bugzilla is affected by an access validation vulnerability. This issue is due to a failure in the application to do proper authentication before permitting changes to bug flags.
An attacker could exploit this vulnerability to retrieve an emailed copy of the summary of the bug; other attacks may also be possible. Information obtained may aid in attacks against the system reported in the bug.
It should be noted users of the 'request_group' or 'grant_group' features of the 2.19 versions of Bugzilla may not be affected by this vulnerability. Those features state the permissions on the changing of flag settings.
Bugzilla is affected by an access validation vulnerability. This issue is due to a failure in the application to do proper authentication before permitting changes to bug flags.
An attacker could exploit this vulnerability to retrieve an emailed copy of the summary of the bug; other attacks may also be possible. Information obtained may aid in attacks against the system reported in the bug.
It should be noted users of the 'request_group' or 'grant_group' features of the 2.19 versions of Bugzilla may not be affected by this vulnerability. Those features state the permissions on the changing of flag settings.
Exploit / POC
Bugzilla Unauthorized Flag Change Access Validation Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Bugzilla Unauthorized Flag Change Access Validation Vulnerability
Solution:
The vendor has addressed this issue in the stable Bugzilla version 2.18.2; earlier versions are reported vulnerable. Users of the development snapshot should upgrade to the latest candidate release 2.20rc1.
Gentoo has released security advisory GLSA 200507-12 addressing this issue. Gentoo recommends all Bugzilla users should upgrade to the latest available version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/bugzilla-2.18.3"
Mozilla Bugzilla 2.17.1
Mozilla Bugzilla 2.17.3
Mozilla Bugzilla 2.17.4
Mozilla Bugzilla 2.17.5
Mozilla Bugzilla 2.17.6
Mozilla Bugzilla 2.17.7
Mozilla Bugzilla 2.18 rc1
Mozilla Bugzilla 2.18 rc3
Mozilla Bugzilla 2.18 rc2
Mozilla Bugzilla 2.19.1
Mozilla Bugzilla 2.19.2
Mozilla Bugzilla 2.19.3
Solution:
The vendor has addressed this issue in the stable Bugzilla version 2.18.2; earlier versions are reported vulnerable. Users of the development snapshot should upgrade to the latest candidate release 2.20rc1.
Gentoo has released security advisory GLSA 200507-12 addressing this issue. Gentoo recommends all Bugzilla users should upgrade to the latest available version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/bugzilla-2.18.3"
Mozilla Bugzilla 2.17.1
-
Mozilla bugzilla-2.18.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18.2.tar.gz
Mozilla Bugzilla 2.17.3
-
Mozilla bugzilla-2.18.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18.2.tar.gz
Mozilla Bugzilla 2.17.4
-
Mozilla bugzilla-2.18.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18.2.tar.gz
Mozilla Bugzilla 2.17.5
-
Mozilla bugzilla-2.18.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18.2.tar.gz
Mozilla Bugzilla 2.17.6
-
Mozilla bugzilla-2.18.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18.2.tar.gz
Mozilla Bugzilla 2.17.7
-
Mozilla bugzilla-2.18.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18.2.tar.gz
Mozilla Bugzilla 2.18 rc1
-
Mozilla bugzilla-2.18.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18.2.tar.gz
Mozilla Bugzilla 2.18 rc3
-
Mozilla bugzilla-2.18.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18.2.tar.gz
Mozilla Bugzilla 2.18 rc2
-
Mozilla bugzilla-2.18.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.18.2.tar.gz
Mozilla Bugzilla 2.19.1
-
Mozilla bugzilla-2.20rc1.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.20rc1.tar.g z
Mozilla Bugzilla 2.19.2
-
Mozilla bugzilla-2.20rc1.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.20rc1.tar.g z
Mozilla Bugzilla 2.19.3
-
Mozilla bugzilla-2.20rc1.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.20rc1.tar.g z
References
Bugzilla Unauthorized Flag Change Access Validation Vulnerability
References:
References:
- 2.18.1, 2.19.3 Security Advisory (Mozilla - Bugzilla)
- Bugzilla Homepage (Mozilla)