CVE-2002-1197: High severity Bugzilla vulnerability
Published Oct 28, 2002
·Updated
bugzillaemailappend.pl in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, allows remote attackers to execute arbitrary code via shell metacharacters in a system call to processmail.
Affected Software
5 affected components
Bugzilla=2.14
Bugzilla=2.14.1
Bugzilla=2.14.2
Bugzilla=2.14.3
Bugzilla=2.16
Event History
Oct 28, 2002
CVE Published
05:00 AM
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1197?
CVE-2002-1197 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2002-1197?
To fix CVE-2002-1197, upgrade Bugzilla to version 2.14.4 or 2.16.1 or later.
3
What are the affected versions in CVE-2002-1197?
CVE-2002-1197 affects Bugzilla versions 2.14.x before 2.14.4 and 2.16.x before 2.16.1.
4
Can CVE-2002-1197 be exploited remotely?
Yes, CVE-2002-1197 can be exploited remotely by attackers using shell metacharacters.
5
What is the impact of CVE-2002-1197?
The impact of CVE-2002-1197 includes the execution of arbitrary code on the vulnerable Bugzilla installation.