Vulnerability Name: | CVE-2002-1196 (CCN-10233) | ||||||||
Assigned: | 2002-10-01 | ||||||||
Published: | 2002-10-01 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: Bugzilla Web site Bug 167485 - When "usebuggroups" is on, then assigning of group_id is in error Source: CONFIRM Type: UNKNOWN http://bugzilla.mozilla.org/show_bug.cgi?id=167485#c12 Source: MITRE Type: CNA CVE-2002-1196 Source: BUGTRAQ Type: UNKNOWN 20021001 [BUGZILLA] Security Advisory Source: CCN Type: Bugzilla Security Advisory October 1st, 2002 Bugzilla Security Advisory for v2.14.3 and v2.16 Source: DEBIAN Type: Patch, Vendor Advisory DSA-173 Source: DEBIAN Type: DSA-173 bugzilla -- privilege escalation Source: XF Type: Vendor Advisory bugzilla-usebuggroups-permissions-leak(10233) Source: CCN Type: OSVDB ID: 6355 Bugzilla editproducts.cgi usebuggroups Privilege Escalation Source: BID Type: UNKNOWN 5843 Source: CCN Type: BID-5843 Bugzilla Group Creation With Elevated Privileges Vulnerability Source: XF Type: UNKNOWN bugzilla-usebuggroups-permissions-leak(10233) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |