Bugzilla Insecure Temporary File Handling Vulnerabilities
BID:7412
Info
Bugzilla Insecure Temporary File Handling Vulnerabilities
| Bugtraq ID: | 7412 |
| Class: | Design Error |
| CVE: |
CVE-2003-0603 |
| Remote: | No |
| Local: | No |
| Published: | Apr 24 2003 12:00AM |
| Updated: | Jul 11 2009 09:07PM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
Mozilla Bugzilla 2.17.3 Mozilla Bugzilla 2.17.1 Mozilla Bugzilla 2.17 Mozilla Bugzilla 2.16.2 Mozilla Bugzilla 2.16.1 Mozilla Bugzilla 2.16 Mozilla Bugzilla 2.14.5 Mozilla Bugzilla 2.14.4 Mozilla Bugzilla 2.14.3 Mozilla Bugzilla 2.14.2 Mozilla Bugzilla 2.14.1 Mozilla Bugzilla 2.14 Mozilla Bugzilla 2.12 Mozilla Bugzilla 2.10 |
| Not Vulnerable: |
Mozilla Bugzilla 2.17.4 Mozilla Bugzilla 2.16.3 |
Discussion
Bugzilla Insecure Temporary File Handling Vulnerabilities
Bugzilla creates temporary files insecurely. Multiple instances of this problem were reported. This could permit local attacks to mount symbolic link attacks which could cause files writeable by the web server hosting Bugzilla to be corrupted or overwritten.
Bugzilla creates temporary files insecurely. Multiple instances of this problem were reported. This could permit local attacks to mount symbolic link attacks which could cause files writeable by the web server hosting Bugzilla to be corrupted or overwritten.
Exploit / POC
Bugzilla Insecure Temporary File Handling Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.