Bugzilla Data/Mining Directory Insecure Permissions Vulnerability
BID:6502
Info
Bugzilla Data/Mining Directory Insecure Permissions Vulnerability
| Bugtraq ID: | 6502 |
| Class: | Configuration Error |
| CVE: |
CVE-2003-0012 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 02 2003 12:00AM |
| Updated: | Jul 11 2009 07:17PM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
Mozilla Bugzilla 2.17.1 Mozilla Bugzilla 2.17 Mozilla Bugzilla 2.16.1 Mozilla Bugzilla 2.16 Mozilla Bugzilla 2.14.4 Mozilla Bugzilla 2.14.3 Mozilla Bugzilla 2.14.2 Mozilla Bugzilla 2.14.1 Mozilla Bugzilla 2.14 |
| Not Vulnerable: |
Mozilla Bugzilla 2.17.3 Mozilla Bugzilla 2.16.2 Mozilla Bugzilla 2.14.5 |
Discussion
Bugzilla Data/Mining Directory Insecure Permissions Vulnerability
Bugzilla ships with a data collection script that sets insecure permissions on the data/mining directory each time it is run. This script is intended to be run as a nightly cron job. As a result, this vulnerability may provide a local attacker with a window of opportunity to alter the contents of the data/mining directory.
Bugzilla ships with a data collection script that sets insecure permissions on the data/mining directory each time it is run. This script is intended to be run as a nightly cron job. As a result, this vulnerability may provide a local attacker with a window of opportunity to alter the contents of the data/mining directory.
Exploit / POC
Bugzilla Data/Mining Directory Insecure Permissions Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Bugzilla Data/Mining Directory Insecure Permissions Vulnerability
Solution:
Debian has released a security advisory (DSA 230-1) containing fixes. Users are advised to upgrade as soon as possible.
The vendor has addressed this issue in Bugzilla 2.14.5, 2.16.2 and 2.17.3. Patches for 2.14.4 and 2.16.1 have also been made available.
Mozilla Bugzilla 2.14
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.17.1
Solution:
Debian has released a security advisory (DSA 230-1) containing fixes. Users are advised to upgrade as soon as possible.
The vendor has addressed this issue in Bugzilla 2.14.5, 2.16.2 and 2.17.3. Patches for 2.14.4 and 2.16.1 have also been made available.
Mozilla Bugzilla 2.14
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.14.1
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.14.2
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html -
Debian bugzilla-doc_2.14.2-0woody4_all.deb
http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla-doc_2 .14.2-0woody4_all.deb -
Debian bugzilla_2.14.2-0woody4_all.deb
http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla_2.14. 2-0woody4_all.deb
Mozilla Bugzilla 2.14.3
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.14.4
-
Bugzilla bugzilla-2.14.4-to-2.14.5.diff.gz
http://ftp.mozilla.org/pub/webtools/bugzilla-2.14.4-to-2.14.5.diff.gz -
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.16
-
Bugzilla Bugzilla 2.16.2
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.16.1
-
Bugzilla bugzilla-2.16.1-to-2.16.2.diff.gz
http://ftp.mozilla.org/pub/webtools/bugzilla-2.16.1-to-2.16.2.diff.gz -
Bugzilla Bugzilla 2.16.2
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.17
-
Bugzilla Bugzilla 2.17.3
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.17.1
-
Bugzilla Bugzilla 2.17.3
http://www.bugzilla.org/download.html
References
Bugzilla Data/Mining Directory Insecure Permissions Vulnerability
References:
References:
- Bugzilla Homepage (Mozilla)
- [BUGZILLA] Security Advisory - remote database password disclosure (David Miller
)