Description
editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/5843
Patch, Vendor Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2002/dsa-173
Vendor Advisory vdb-entry
x_refsource_xf
http://www.iss.net/security_center/static/10233.php
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=167485#c12
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103349804226566&w=2
Scores
EPSS
0.0159
EPSS Percentile
73.0%
Details
Status
published
Products (5)
mozilla/bugzilla
2.14
mozilla/bugzilla
2.14.1
mozilla/bugzilla
2.14.2
mozilla/bugzilla
2.14.3
mozilla/bugzilla
2.16
Published
Oct 28, 2002
Tracked Since
Feb 18, 2026