First published: Wed Dec 28 2005(Updated: )
The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.16.8 | |
Mozilla Bugzilla | =2.16.1 | |
Mozilla Bugzilla | =2.16.2 | |
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.16.9 | |
Mozilla Bugzilla | =2.14.2 | |
Mozilla Bugzilla | =2.14.3 | |
Mozilla Bugzilla | =2.14.4 | |
Mozilla Bugzilla | =2.16.7 | |
Mozilla Bugzilla | =2.16.4 | |
Mozilla Bugzilla | =2.12 | |
Mozilla Bugzilla | =2.16.3 | |
Mozilla Bugzilla | =2.14.5 | |
Mozilla Bugzilla | =2.16.6 | |
Mozilla Bugzilla | =2.9 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.16.5 | |
Mozilla Bugzilla | =2.14 | |
Mozilla Bugzilla | =2.16.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4534 has a moderate severity level due to the potential for local users to overwrite arbitrary files.
To fix CVE-2005-4534, update Bugzilla to a version later than 2.16.10 that addresses this vulnerability.
CVE-2005-4534 affects Bugzilla versions from 2.9 to 2.16.10.
In the context of CVE-2005-4534, a symlink attack allows local users to create symbolic links to overwrite sensitive files.
No, CVE-2005-4534 is limited to exploitation by local users only.