7.5
CVSSv2

CVE-2002-1196

Published: 28/10/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

editproducts.cgi in Bugzilla 2.14.x prior to 2.14.4, and 2.16.x prior to 2.16.1, when the "usebuggroups" feature is enabled and more than 47 groups are specified, does not properly calculate bit values for large numbers, which grants extra permissions to users via known features of Perl math that set multiple bits.

Vulnerable Product Search on Vulmon Subscribe to Product

mozilla bugzilla 2.14

mozilla bugzilla 2.14.1

mozilla bugzilla 2.14.2

mozilla bugzilla 2.14.3

mozilla bugzilla 2.16

Vendor Advisories

The developers of Bugzilla, a web-based bug tracking system, discovered a problem in the handling of more than 47 groups When a new product is added to an installation with 47 groups or more and "usebuggroups" is enabled, the new group will be assigned a groupset bit using Perl math that is not exact beyond 248 This results in the new group being ...