CVE-2002-1196

Bugzilla <2.14.4-2.16.1 - Privilege Escalation

Title source: llm
STIX 2.1

Description

editproducts.cgi in Bugzilla 2.14.x before 2.14.4, and 2.16.x before 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/5843
Patch, Vendor Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2002/dsa-173
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10233.php
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=167485#c12
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103349804226566&w=2

Scores

EPSS 0.0159
EPSS Percentile 73.0%

Details

Status published
Products (5)
mozilla/bugzilla 2.14
mozilla/bugzilla 2.14.1
mozilla/bugzilla 2.14.2
mozilla/bugzilla 2.14.3
mozilla/bugzilla 2.16
Published Oct 28, 2002
Tracked Since Feb 18, 2026