CVE-2001-0329: High severity Bugzilla vulnerability
Published May 24, 2001
·Updated
Bugzilla 2.10 allows remote attackers to execute arbitrary commands via shell metacharacters in a username that is then processed by (1) the Bugzillalogin cookie in postbug.cgi, or (2) the who parameter in processbug.cgi.
Affected Software
4 affected components
Bugzilla=2.4
Bugzilla=2.6
Bugzilla=2.8
Bugzilla=2.10
Remediation
Event History
May 24, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0329?
CVE-2001-0329 is classified as a critical vulnerability due to its potential for remote arbitrary code execution.
2
How do I fix CVE-2001-0329?
To fix CVE-2001-0329, upgrade to Bugzilla version 2.12 or later, which addresses this vulnerability.
3
Which versions of Bugzilla are affected by CVE-2001-0329?
CVE-2001-0329 affects Bugzilla versions 2.4, 2.6, 2.8, and 2.10.
4
What type of attack does CVE-2001-0329 facilitate?
CVE-2001-0329 facilitates remote command execution attacks through user input that is improperly sanitized.
5
Who can exploit the vulnerability identified in CVE-2001-0329?
Any remote attacker with access to the affected Bugzilla installation can exploit the vulnerability described in CVE-2001-0329.