First published: Fri Jul 08 2005(Updated: )
The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via process_bug.cgi.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.17.6 | |
Mozilla Bugzilla | =2.19.3 | |
Mozilla Bugzilla | =2.19 | |
Mozilla Bugzilla | =2.18-rc1 | |
Mozilla Bugzilla | =2.17.4 | |
Mozilla Bugzilla | =2.17.1 | |
Mozilla Bugzilla | =2.18.1 | |
Mozilla Bugzilla | =2.19.1 | |
Mozilla Bugzilla | =2.17.5 | |
Mozilla Bugzilla | =2.17.3 | |
Mozilla Bugzilla | =2.18 | |
Mozilla Bugzilla | =2.17.7 | |
Mozilla Bugzilla | =2.18-rc3 | |
Mozilla Bugzilla | =2.18-rc2 | |
Mozilla Bugzilla | =2.19.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2173 has a medium severity as it can allow unauthorized users to modify flags on arbitrary bugs.
To fix CVE-2005-2173, upgrade your Bugzilla installation to version 2.18.2 or later.
CVE-2005-2173 affects Bugzilla versions 2.17.1 to 2.17.7 and 2.18.1 to 2.19.3.
CVE-2005-2173 is a privilege escalation vulnerability related to flag handling in Bugzilla.
An attacker can change flags on bugs they should not access and view bug summaries through process_bug.cgi.