CVE-2002-0809: High severity Bugzilla vulnerability
Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, does not properly handle URL-encoded field names that are generated by some browsers, which could cause certain fields to appear to be unset, which has the effect of removing group permissions on bugs when buglist.cgi is provided with the encoded field names.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0809?
CVE-2002-0809 is considered to have a moderate severity due to its potential impact on group permissions.
How do I fix CVE-2002-0809?
To fix CVE-2002-0809, upgrade Bugzilla to version 2.14.2 or later.
Which versions are affected by CVE-2002-0809?
CVE-2002-0809 affects Bugzilla versions 2.14 and 2.16 prior to 2.16rc2.
What is the impact of CVE-2002-0809 on Bugzilla?
CVE-2002-0809 can cause certain fields to appear unset, potentially removing group permissions on bugs.
Is there any known workaround for CVE-2002-0809?
There are no specified workarounds for CVE-2002-0809; upgrading is the recommended solution.