Bugzilla Local Dependency Graph HTML Injection Vulnerability
BID:6861
Info
Bugzilla Local Dependency Graph HTML Injection Vulnerability
| Bugtraq ID: | 6861 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0602 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 24 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
Mozilla Bugzilla 2.17.3 Mozilla Bugzilla 2.17.1 Mozilla Bugzilla 2.17 Mozilla Bugzilla 2.16.2 Mozilla Bugzilla 2.16.1 Mozilla Bugzilla 2.16 |
| Not Vulnerable: |
Mozilla Bugzilla 2.17.4 Mozilla Bugzilla 2.16.3 |
Discussion
Bugzilla Local Dependency Graph HTML Injection Vulnerability
Bugzilla versions 2.16 and later include a feature that allows users to generate bug dependency graphs on their local system via the GraphViz suite. HTML will not be sanitized when these graphs are generated. Malicious HTML and script code may be included in bug summaries.
This may be exploited to cause HTML or script code to be interpreted by the web client of a user who generate a dependency graph which contains malicious data.
Earlier versions of Bugzilla which are configured use a remote server to generate dependency graphs are not affected by this vulnerability.
Bugzilla versions 2.16 and later include a feature that allows users to generate bug dependency graphs on their local system via the GraphViz suite. HTML will not be sanitized when these graphs are generated. Malicious HTML and script code may be included in bug summaries.
This may be exploited to cause HTML or script code to be interpreted by the web client of a user who generate a dependency graph which contains malicious data.
Earlier versions of Bugzilla which are configured use a remote server to generate dependency graphs are not affected by this vulnerability.
Solution / Fix
Bugzilla Local Dependency Graph HTML Injection Vulnerability
Solution:
The vendor has addressed this issue in Bugzilla 2.16.3 and 2.17.4. Patches may be obtained at the following location:
http://ftp.mozilla.org/pub/webtools/
Full release upgrades and CVS upgrade instructions will be made available here:
http://www.bugzilla.org/download.html
Solution:
The vendor has addressed this issue in Bugzilla 2.16.3 and 2.17.4. Patches may be obtained at the following location:
http://ftp.mozilla.org/pub/webtools/
Full release upgrades and CVS upgrade instructions will be made available here:
http://www.bugzilla.org/download.html
References
Bugzilla Local Dependency Graph HTML Injection Vulnerability
References:
References:
- Bugzilla Homepage (Mozilla)