CVE-2002-0804: High severity Bugzilla vulnerability
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reverse DNS hostname.
Affected Software
Remediation
Event History
Frequently Asked Questions
What versions of Bugzilla are affected by CVE-2002-0804?
CVE-2002-0804 affects Bugzilla versions 2.14, 2.14.1, 2.16-rc1, and 2.16.
What is the severity of CVE-2002-0804?
CVE-2002-0804 is considered a moderate severity vulnerability due to its potential to allow unauthorized access.
How do I fix CVE-2002-0804?
To fix CVE-2002-0804, upgrade Bugzilla to version 2.14.2 or later, or 2.16 rc2 or later.
How does CVE-2002-0804 allow attackers to bypass IP restrictions?
CVE-2002-0804 allows attackers to bypass IP restrictions by connecting with a spoofed reverse DNS hostname when reverse DNS lookups are enabled.
What is the impact of CVE-2002-0804 on Bugzilla installations?
The impact of CVE-2002-0804 on Bugzilla installations can lead to unauthorized access, allowing remote attackers to manipulate bug data.