CVE-2005-4534: High severity Bugzilla vulnerability
Published Dec 28, 2005
·Updated
The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Affected Software
20 affected components
Bugzilla=2.9
Bugzilla=2.10
Bugzilla=2.12
Bugzilla=2.14
Bugzilla=2.14.1
Bugzilla=2.14.2
Bugzilla=2.14.3
Bugzilla=2.14.4
Bugzilla=2.14.5
Bugzilla=2.16
Bugzilla=2.16.1
Bugzilla=2.16.2
Bugzilla=2.16.3
Bugzilla=2.16.4
Bugzilla=2.16.5
Bugzilla=2.16.6
Bugzilla=2.16.7
Bugzilla=2.16.8
Bugzilla=2.16.9
Bugzilla=2.16.10
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 28, 2005
CVE Published
02:03 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-4534?
CVE-2005-4534 has a moderate severity level due to the potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2005-4534?
To fix CVE-2005-4534, update Bugzilla to a version later than 2.16.10 that addresses this vulnerability.
3
What versions of Bugzilla are affected by CVE-2005-4534?
CVE-2005-4534 affects Bugzilla versions from 2.9 to 2.16.10.
4
What is a symlink attack in the context of CVE-2005-4534?
In the context of CVE-2005-4534, a symlink attack allows local users to create symbolic links to overwrite sensitive files.
5
Can remote users exploit CVE-2005-4534?
No, CVE-2005-4534 is limited to exploitation by local users only.