Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabilities
BID:22380
Info
Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabilities
| Bugtraq ID: | 22380 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-0792 CVE-2007-0791 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 03 2007 12:00AM |
| Updated: | Jul 06 2016 02:40PM |
| Credit: | Frédéric Buclin, Dave Miller, Olav Vitters and Max Kanat-Alexander are credited with discovering these issues. |
| Vulnerable: |
Mozilla Bugzilla 2.23.3 Mozilla Bugzilla 2.23.2 Mozilla Bugzilla 2.22.1 Mozilla Bugzilla 2.21.2 Mozilla Bugzilla 2.21.1 Mozilla Bugzilla 2.21 Mozilla Bugzilla 2.20.3 Mozilla Bugzilla 2.20.2 Mozilla Bugzilla 2.20.1 Mozilla Bugzilla 2.22 RC1 Mozilla Bugzilla 2.22 |
| Not Vulnerable: |
Mozilla Bugzilla 2.23.4 Mozilla Bugzilla 2.22.2 Mozilla Bugzilla 2.20.4 |
Discussion
Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabilities
Bugzilla is prone to an information-disclosure and an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input and to protect sensitive information from unauthorized users.
Attackers may exploit these issues to execute script code in the context of the affected site or to obtain sensitive information. Arbitrary code execution may allow attackers to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Bugzilla 2.20.1 and above are affected by the HTML-injection vulnerability; only the development snapshot version 2.23.3 is vulnerable to the information-disclosure issue.
Bugzilla is prone to an information-disclosure and an HTML-injection vulnerability because the application fails to properly sanitize user-supplied input and to protect sensitive information from unauthorized users.
Attackers may exploit these issues to execute script code in the context of the affected site or to obtain sensitive information. Arbitrary code execution may allow attackers to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
Bugzilla 2.20.1 and above are affected by the HTML-injection vulnerability; only the development snapshot version 2.23.3 is vulnerable to the information-disclosure issue.
Exploit / POC
Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabilities
Solution:
The vendor released fixes to address these issues. Please see the references section for more information.
Mozilla Bugzilla 2.22 RC1
Mozilla Bugzilla 2.22
Mozilla Bugzilla 2.20.1
Mozilla Bugzilla 2.20.2
Mozilla Bugzilla 2.20.3
Mozilla Bugzilla 2.21
Mozilla Bugzilla 2.21.1
Mozilla Bugzilla 2.21.2
Mozilla Bugzilla 2.22.1
Mozilla Bugzilla 2.23.2
Mozilla Bugzilla 2.23.3
Solution:
The vendor released fixes to address these issues. Please see the references section for more information.
Mozilla Bugzilla 2.22 RC1
-
Mozilla bugzilla-2.22.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.22.2.tar.gz
Mozilla Bugzilla 2.22
-
Mozilla bugzilla-2.22.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.22.2.tar.gz
Mozilla Bugzilla 2.20.1
-
Mozilla bugzilla-2.20.4.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.20.4.tar.gz
Mozilla Bugzilla 2.20.2
-
Mozilla bugzilla-2.20.4.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.20.4.tar.gz
Mozilla Bugzilla 2.20.3
-
Mozilla bugzilla-2.20.4.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.20.4.tar.gz
Mozilla Bugzilla 2.21
-
Mozilla bugzilla-2.22.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.22.2.tar.gz
Mozilla Bugzilla 2.21.1
-
Mozilla bugzilla-2.22.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.22.2.tar.gz
Mozilla Bugzilla 2.21.2
-
Mozilla bugzilla-2.22.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.22.2.tar.gz
Mozilla Bugzilla 2.22.1
-
Mozilla bugzilla-2.22.2.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.22.2.tar.gz
Mozilla Bugzilla 2.23.2
-
Mozilla bugzilla-2.23.4.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.23.4.tar.gz
Mozilla Bugzilla 2.23.3
-
Mozilla bugzilla-2.23.4.tar.gz
http://ftp.mozilla.org/pub/mozilla.org/webtools/bugzilla-2.23.4.tar.gz
References
Mozilla Bugzilla HTML Injection And Information disclosure Vulnerabilities
References:
References:
- Bugzilla Homepage (Mozilla)
- 2.20.3, 2.22.1, and 2.23.3 Security Advisory (Bugzilla Team)
- Security Advisory for Bugzilla 2.20.3, 2.22.1, and 2.23.3 (Bugzilla Team)