CVE-2002-0808: High severity Bugzilla vulnerability
Published Aug 12, 2002
·Updated
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, when performing a mass change, sets the groupset of all bugs to the groupset of the first bug, which could inadvertently cause insecure groupset permissions to be assigned to some bugs.
Affected Software
4 affected components
Bugzilla=2.16-rc1
Bugzilla=2.16
Bugzilla=2.14.1
Bugzilla=2.14
Remediation
Event History
Aug 12, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0808?
CVE-2002-0808 has a moderate severity rating due to the potential for insecure permission settings.
2
How do I fix CVE-2002-0808?
To fix CVE-2002-0808, upgrade Bugzilla to version 2.14.2 or 2.16rc2 or later.
3
Which versions of Bugzilla are affected by CVE-2002-0808?
CVE-2002-0808 affects Bugzilla versions 2.14 through 2.14.1 and 2.16 before 2.16rc2.
4
What does CVE-2002-0808 vulnerability affect?
CVE-2002-0808 affects the groupset permissions for bugs within Bugzilla during mass change operations.
5
Is CVE-2002-0808 a known issue?
Yes, CVE-2002-0808 is a documented vulnerability in Bugzilla that has been publicly acknowledged.