CVE-2002-0805: Medium severity Bugzilla vulnerability
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, (1) creates new directories with world-writable permissions, and (2) creates the params file with world-writable permissions, which allows local users to modify the files and execute code.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0805?
CVE-2002-0805 is rated as a high severity vulnerability due to its world-writable permissions that allow local users to modify files.
How do I fix CVE-2002-0805?
To fix CVE-2002-0805, upgrade Bugzilla to version 2.14.2 or 2.16rc2 or later.
What versions of Bugzilla are affected by CVE-2002-0805?
CVE-2002-0805 affects Bugzilla versions 2.14 and earlier, as well as 2.16 up to version 2.16rc1.
What risks are associated with CVE-2002-0805?
The risks associated with CVE-2002-0805 include potential unauthorized file modification and code execution by local users.
Is it safe to use Bugzilla 2.16rc1 or earlier?
No, using Bugzilla 2.16rc1 or earlier is not safe due to the security vulnerabilities present in those versions.