![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2002-1196 |
Description: | editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.53428 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2002-1196 BugTraq ID: 5843 http://www.securityfocus.com/bid/5843 Bugtraq: 20021001 [BUGZILLA] Security Advisory (Google Search) http://marc.info/?l=bugtraq&m=103349804226566&w=2 Debian Security Information: DSA-173 (Google Search) http://www.debian.org/security/2002/dsa-173 XForce ISS Database: bugzilla-usebuggroups-permissions-leak(10233) http://www.iss.net/security_center/static/10233.php |