![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.53428 |
Category: | Debian Local Security Checks |
Title: | Debian Security Advisory DSA 173-1 (bugzilla) |
Summary: | The remote host is missing an update to bugzilla;announced via advisory DSA 173-1. |
Description: | Summary: The remote host is missing an update to bugzilla announced via advisory DSA 173-1. Vulnerability Insight: The developers of Bugzilla, a web-based bug tracking system, discovered a problem in the handling of more than 47 groups. When a new product is added to an installation with 47 groups or more and usebuggroups is enabled, the new group will be assigned a groupset bit using Perl math that is not exact beyond 2^48. This results in the new group being defined with a bit that has several bits set. As users are given access to the new group, those users will also gain access to spurious lower group privileges. Also, group bits were not always reused when groups were deleted. This problem has been fixed in version 2.14.2-0woody2 for the current stable distribution (woody) and will soon be fixed in the unstable distribution (sid). The old stable distribution (potato) doesn't contain a bugzilla package. Solution: We recommend that you upgrade your bugzilla package. CVSS Score: 7.5 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2002-1196 BugTraq ID: 5843 http://www.securityfocus.com/bid/5843 Bugtraq: 20021001 [BUGZILLA] Security Advisory (Google Search) http://marc.info/?l=bugtraq&m=103349804226566&w=2 Debian Security Information: DSA-173 (Google Search) http://www.debian.org/security/2002/dsa-173 http://www.iss.net/security_center/static/10233.php |
Copyright | Copyright (C) 2008 E-Soft Inc. |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |