CVE-2002-1196: High severity Bugzilla vulnerability
editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1196?
CVE-2002-1196 has been classified as a moderate severity vulnerability due to its potential to grant extra permissions to users.
What software versions are vulnerable to CVE-2002-1196?
CVE-2002-1196 affects Bugzilla versions 2.14.x before 2.14.4 and 2.16.x before 2.16.1 when the "usebuggroups" feature is enabled.
How do I fix CVE-2002-1196?
To fix CVE-2002-1196, upgrade Bugzilla to version 2.14.4 or 2.16.1 or later.
What causes the vulnerability in CVE-2002-1196?
CVE-2002-1196 is caused by incorrect bit value calculations for large numbers in the editproducts.cgi script.
What is the impact of not addressing CVE-2002-1196?
Failing to address CVE-2002-1196 may allow unauthorized users to gain elevated permissions in Bugzilla.