| VID |
21384 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The Bugzilla bug-tracking system, according to its version number, has multiple security vulnerabilities. Bugzilla is a Web-based bug-tracking system, based on Perl and MySQL. Bugzilla versions 2.9 through 2.18rc2 and version 2.19 (cvs) are vulnerable to various flaws that may allow a remote attacker to view private comments and attachments or to perform an unauthorized bug change.
* Note: This check solely relied on the version number of Bugzilla in the remote Web server to assess this vulnerability, so this might be a false positive.
* References: http://archives.neohapsis.com/archives/bugtraq/2004-10/0251.html
* Platforms Affected: Mozilla Project, Bugzilla 2.9 to 2.18rc2 Mozilla Project, Bugzilla 2.19 (cvs) Any operating system Any version |
| Recommendation |
Upgrade to the latest version of Bugzilla (2.16.7 or 2.18rc3, or 2.19.1(cvs) or later), available from the Bugzilla Download Web site at http://www.bugzilla.org/download/ |
| Related URL |
CVE-2004-1633,CVE-2004-1634 (CVE) |
| Related URL |
11511 (SecurityFocus) |
| Related URL |
17840,17841 (ISS) |
|