Bugzilla Syncshadowdb Insecure Temporary File Creation Vulnerability
BID:16061
Info
Bugzilla Syncshadowdb Insecure Temporary File Creation Vulnerability
| Bugtraq ID: | 16061 |
| Class: | Design Error |
| CVE: |
CVE-2005-4534 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 26 2005 12:00AM |
| Updated: | Nov 15 2007 12:38AM |
| Credit: | Javier Fernandez-Sanguino Pena is credited with the discovery of this vulnerability. |
| Vulnerable: |
Mozilla Bugzilla 2.16.9 Mozilla Bugzilla 2.16.8 Mozilla Bugzilla 2.16.7 Mozilla Bugzilla 2.16.6 Mozilla Bugzilla 2.16.5 Mozilla Bugzilla 2.16.4 Mozilla Bugzilla 2.16.3 Mozilla Bugzilla 2.16.2 Mozilla Bugzilla 2.16.1 Mozilla Bugzilla 2.16 .10 Mozilla Bugzilla 2.16 Mozilla Bugzilla 2.14.5 Mozilla Bugzilla 2.14.4 Mozilla Bugzilla 2.14.3 Mozilla Bugzilla 2.14.2 Mozilla Bugzilla 2.14.1 Mozilla Bugzilla 2.14 Mozilla Bugzilla 2.12 Mozilla Bugzilla 2.10 Mozilla Bugzilla 2.9 |
| Not Vulnerable: | |
Discussion
Bugzilla Syncshadowdb Insecure Temporary File Creation Vulnerability
Bugzilla creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Bugzilla creates temporary files in an insecure manner.
Exploitation would most likely result in loss of data or a denial of service if critical files are overwritten in the attack. Other attacks may be possible as well.
Exploit / POC
Bugzilla Syncshadowdb Insecure Temporary File Creation Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Bugzilla Syncshadowdb Insecure Temporary File Creation Vulnerability
Solution:
The vendor has released a patch to address this issue. This patch will be included in the upcoming 2.16.11 release of Bugzilla as well.
Debian has released security advisory DSA 1208-1 to address this issue; please see the references for details.
Mozilla Bugzilla 2.16 .10
Mozilla Bugzilla 2.16.7
Solution:
The vendor has released a patch to address this issue. This patch will be included in the upcoming 2.16.11 release of Bugzilla as well.
Debian has released security advisory DSA 1208-1 to address this issue; please see the references for details.
Mozilla Bugzilla 2.16 .10
-
Mozilla syncshadowdb patch for 2.16.10
https://bugzilla.mozilla.org/attachment.cgi?id=203870
Mozilla Bugzilla 2.16.7
-
Debian bugzilla-doc_2.16.7-7sarge2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla-doc_2 .16.7-7sarge2_all.deb -
Debian bugzilla_2.16.7-7sarge2_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla_2.16. 7-7sarge2_all.deb
References
Bugzilla Syncshadowdb Insecure Temporary File Creation Vulnerability
References:
References: