Vulnerability Name: | CVE-2003-0012 (CCN-10971) | ||||||||
Assigned: | 2003-01-02 | ||||||||
Published: | 2003-01-02 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | The data collection script for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: CCN Type: Bugzilla Bug 183188 data/mining is world writable after each run of collectstats.pl Source: MITRE Type: CNA CVE-2003-0012 Source: BUGTRAQ Type: UNKNOWN 20030102 [BUGZILLA] Security Advisory - remote database password disclosure Source: CCN Type: RHSA-2003-012 Updated CVS packages available Source: CCN Type: Bugzilla Security Advisory, January 2nd, 2003 remote database password disclosure Source: DEBIAN Type: UNKNOWN DSA-230 Source: DEBIAN Type: DSA-230 bugzilla -- insecure permissions Source: XF Type: Vendor Advisory bugzilla-mining-world-writable(10971) Source: CCN Type: OSVDB ID: 6352 Bugzilla collectstats.pl Permission Failure Source: REDHAT Type: UNKNOWN RHSA-2003:012 Source: BID Type: UNKNOWN 6502 Source: CCN Type: BID-6502 Bugzilla Data/Mining Directory Insecure Permissions Vulnerability Source: XF Type: UNKNOWN bugzilla-mining-world-writable(10971) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |