CVE-2005-2174: Race Condition
Published Jul 8, 2005
·Updated
Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.
Affected Software
15 affected components
Bugzilla=2.17.6
Bugzilla=2.19.3
Bugzilla=2.19
Bugzilla=2.18-rc1
Bugzilla=2.17.4
Bugzilla=2.17.1
Bugzilla=2.18.1
Bugzilla=2.19.1
Bugzilla=2.17.5
Bugzilla=2.17.3
Bugzilla=2.18
Bugzilla=2.17.7
Bugzilla=2.18-rc3
Bugzilla=2.18-rc2
Bugzilla=2.19.2
Remediation
Patch Available
Patch Available
Event History
Jul 8, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2174?
CVE-2005-2174 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2005-2174?
To fix CVE-2005-2174, you should upgrade to Bugzilla version 2.18.2 or later.
3
What types of attacks are possible with CVE-2005-2174?
CVE-2005-2174 allows attackers to gain unauthorized access to Bugzilla information before it is marked private.
4
Which Bugzilla versions are affected by CVE-2005-2174?
CVE-2005-2174 affects Bugzilla versions 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1.
5
What is the nature of the vulnerability in CVE-2005-2174?
CVE-2005-2174 involves a race condition that allows data leaks during MySQL replication.