First published: Mon Aug 12 2002(Updated: )
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when configured to perform reverse DNS lookups, allows remote attackers to bypass IP restrictions by connecting from a system with a spoofed reverse DNS hostname.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.16-rc1 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0804 affects Bugzilla versions 2.14, 2.14.1, 2.16-rc1, and 2.16.
CVE-2002-0804 is considered a moderate severity vulnerability due to its potential to allow unauthorized access.
To fix CVE-2002-0804, upgrade Bugzilla to version 2.14.2 or later, or 2.16 rc2 or later.
CVE-2002-0804 allows attackers to bypass IP restrictions by connecting with a spoofed reverse DNS hostname when reverse DNS lookups are enabled.
The impact of CVE-2002-0804 on Bugzilla installations can lead to unauthorized access, allowing remote attackers to manipulate bug data.