Executive Summary
Summary | |
---|---|
Title | New bugzilla packages fix several vulnerabilities |
Informations | |||
---|---|---|---|
Name | DSA-1208 | First vendor Publication | 2006-11-11 |
Vendor | Debian | Last vendor Modification | 2006-11-11 |
Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 7.5 | Attack Range | Network |
Cvss Impact Score | 6.4 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Several remote vulnerabilities have been discovered in the Bugzilla bug tracking system, which may lead to the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-4534 Javier Fernández-Sanguino Peña discovered that insecure temporary file usage may lead to denial of service through a symlink attack. CVE-2006-5453 Several cross-site scripting vulnerabilities may lead to injection of arbitrary web script code. For the stable distribution (sarge) these problems have been fixed in version 2.16.7-7sarge2. For the upcoming stable distribution (etch) these problems have been fixed in version 2.22.1-1. For the unstable distribution (sid) these problems have been fixed in version 2.22.1-1. We recommend that you upgrade your bugzilla packages. |
Original Source
Url : http://www.debian.org/security/2006/dsa-1208 |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2008-09-24 | Name : Gentoo Security Advisory GLSA 200611-04 (bugzilla) File : nvt/glsa_200611_04.nasl |
2008-09-04 | Name : FreeBSD Ports: bugzilla, ja-bugzilla File : nvt/freebsd_bugzilla2.nasl |
2008-01-17 | Name : Debian Security Advisory DSA 1208-1 (bugzilla) File : nvt/deb_1208_1.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
29545 | Bugzilla Multiple Description Field XSS Bugzilla contains a flaw that allows a remote cross site scripting attack. This flaw exists because the application does not validate various description field variables upon submission. This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity. |
22061 | Bugzilla syncshadowdb Symlink Arbitrary File Overwrite |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2006-11-20 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1208.nasl - Type : ACT_GATHER_INFO |
2006-11-20 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_6d68618a719911dba2ad000c6ec775d9.nasl - Type : ACT_GATHER_INFO |
2006-11-20 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-200611-04.nasl - Type : ACT_GATHER_INFO |
Alert History
Date | Informations |
---|---|
2014-02-17 11:26:19 |
|