Bugzilla process_bug.cgi Duplicate Bug Disclosure Vulnerability
BID:3273
Info
Bugzilla process_bug.cgi Duplicate Bug Disclosure Vulnerability
| Bugtraq ID: | 3273 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2001 12:00AM |
| Updated: | Aug 29 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on August 29th, 2001 by David Miller <[email protected]>. |
| Vulnerable: |
Mozilla Bugzilla 2.12 Mozilla Bugzilla 2.10 Mozilla Bugzilla 2.8 Mozilla Bugzilla 2.6 Mozilla Bugzilla 2.4 |
| Not Vulnerable: |
Mozilla Bugzilla 2.14 |
Discussion
Bugzilla process_bug.cgi Duplicate Bug Disclosure Vulnerability
Bugzilla is a free, open source bug tracking and reporting appplication. It allows users to submit bugs, offers a forum for discussing bugs, keeps track of the status of bugs, and can restrict who has access to bug information.
A vulnerability in 'process_bug.cgi' makes it possible to bypass the access controls for bugs that are designated as restricted by Bugzilla. If a user adds a new bug as a duplicate of a restricted existing bug then they will be added to the cclist of the existing bug. This allows the user to bypass the group-based access controls enforced by Bugzilla.
Bugzilla is a free, open source bug tracking and reporting appplication. It allows users to submit bugs, offers a forum for discussing bugs, keeps track of the status of bugs, and can restrict who has access to bug information.
A vulnerability in 'process_bug.cgi' makes it possible to bypass the access controls for bugs that are designated as restricted by Bugzilla. If a user adds a new bug as a duplicate of a restricted existing bug then they will be added to the cclist of the existing bug. This allows the user to bypass the group-based access controls enforced by Bugzilla.
References
Bugzilla process_bug.cgi Duplicate Bug Disclosure Vulnerability
References:
References: