First published: Mon Oct 28 2002(Updated: )
editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.14.2 | |
Mozilla Bugzilla | =2.14.3 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1196 has been classified as a moderate severity vulnerability due to its potential to grant extra permissions to users.
CVE-2002-1196 affects Bugzilla versions 2.14.x before 2.14.4 and 2.16.x before 2.16.1 when the "usebuggroups" feature is enabled.
To fix CVE-2002-1196, upgrade Bugzilla to version 2.14.4 or 2.16.1 or later.
CVE-2002-1196 is caused by incorrect bit value calculations for large numbers in the editproducts.cgi script.
Failing to address CVE-2002-1196 may allow unauthorized users to gain elevated permissions in Bugzilla.