CVE-2001-1405: Low severity Bugzilla vulnerability
Published Sep 10, 2001
·Updated
Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.
Affected Software
6 affected components
Bugzilla=2.10
Bugzilla=2.6
Bugzilla=2.4
Bugzilla=2.12
Bugzilla=2.8
Bugzilla=2.14
Remediation
Patch Available
Event History
Sep 10, 2001
CVE Published
04:00 AM
Aug 31, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1405?
CVE-2001-1405 is considered a denial of service vulnerability that may lead to significant CPU consumption.
2
How do I fix CVE-2001-1405?
To fix CVE-2001-1405, upgrade to Bugzilla version 2.14 or later to restrict access to sanitycheck.cgi.
3
Which versions of Bugzilla are affected by CVE-2001-1405?
CVE-2001-1405 affects Bugzilla versions 2.10, 2.4, 2.6, 2.8, and 2.12.
4
Can CVE-2001-1405 be exploited remotely?
CVE-2001-1405 does not specify remote exploitation, as it primarily impacts local users by generating excessive requests.
5
What is the impact of exploiting CVE-2001-1405?
Exploiting CVE-2001-1405 can lead to service disruption by overwhelming the server with requests, causing a denial of service.