CVE-2005-2173: Medium severity Bugzilla vulnerability
Published Jul 8, 2005
·Updated
The Flag::validate and Flag::modify functions in Bugzilla 2.17.1 to 2.18.1 and 2.19.1 to 2.19.3 do not verify that the flag ID is appropriate for the given bug or attachment ID, which allows users to change flags on arbitrary bugs and obtain a bug summary via processbug.cgi.
Affected Software
15 affected components
Bugzilla=2.17.1
Bugzilla=2.17.3
Bugzilla=2.17.4
Bugzilla=2.17.5
Bugzilla=2.17.6
Bugzilla=2.17.7
Bugzilla=2.18
Bugzilla=2.18-rc1
Bugzilla=2.18-rc2
Bugzilla=2.18-rc3
Bugzilla=2.18.1
Bugzilla=2.19
Bugzilla=2.19.1
Bugzilla=2.19.2
Bugzilla=2.19.3
Remediation
Patch Available
Patch Available
Event History
Jul 8, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2173?
CVE-2005-2173 has a medium severity as it can allow unauthorized users to modify flags on arbitrary bugs.
2
How do I fix CVE-2005-2173?
To fix CVE-2005-2173, upgrade your Bugzilla installation to version 2.18.2 or later.
3
Which versions are affected by CVE-2005-2173?
CVE-2005-2173 affects Bugzilla versions 2.17.1 to 2.17.7 and 2.18.1 to 2.19.3.
4
What type of vulnerability is CVE-2005-2173?
CVE-2005-2173 is a privilege escalation vulnerability related to flag handling in Bugzilla.
5
What can an attacker do with CVE-2005-2173?
An attacker can change flags on bugs they should not access and view bug summaries through process_bug.cgi.