The data collection script for Bugzilla 2.14.x prior to 2.14.5, 2.16.x prior to 2.16.2, and 2.17.x prior to 2.17.3 sets world-writable permissions for the data/mining directory when it runs, which allows local users to modify or delete the data.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mozilla bugzilla 2.14.4 |
||
mozilla bugzilla 2.16 |
||
mozilla bugzilla 2.14.1 |
||
mozilla bugzilla 2.14.2 |
||
mozilla bugzilla 2.14.3 |
||
mozilla bugzilla 2.14 |
||
mozilla bugzilla 2.17.1 |
||
mozilla bugzilla 2.16.1 |
||
mozilla bugzilla 2.17 |