FreeBSD : Bugzilla multiple security issues (b6587341-4d88-11e4-aef9-20cf30e32f6d)

medium Nessus Plugin ID 78071

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Bugzilla Security Advisory Unauthorized Account Creation An attacker creating a new Bugzilla account can override certain parameters when finalizing the account creation that can lead to the user being created with a different email address than originally requested. The overridden login name could be automatically added to groups based on the group's regular expression setting. Cross-Site Scripting During an audit of the Bugzilla code base, several places were found where cross-site scripting exploits could occur which could allow an attacker to access sensitive information. Information Leak If a new comment was marked private to the insider group, and a flag was set in the same transaction, the comment would be visible to flag recipients even if they were not in the insider group. Social Engineering Search results can be exported as a CSV file which can then be imported into external spreadsheet programs. Specially formatted field values can be interpreted as formulas which can be executed and used to attack a user's computer.

Solution

Update the affected package.

See Also

https://bugzilla.mozilla.org/show_bug.cgi?id=1074812

https://bugzilla.mozilla.org/show_bug.cgi?id=1075578

https://bugzilla.mozilla.org/show_bug.cgi?id=1064140

https://bugzilla.mozilla.org/show_bug.cgi?id=1054702

http://www.nessus.org/u?e3b546f5

Plugin Details

Severity: Medium

ID: 78071

File Name: freebsd_pkg_b65873414d8811e4aef920cf30e32f6d.nasl

Version: 1.5

Type: local

Published: 10/7/2014

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:bugzilla44, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 10/6/2014

Vulnerability Publication Date: 10/6/2014

Reference Information

CVE: CVE-2014-1571, CVE-2014-1572, CVE-2014-1573