FreeBSD : Bugzilla multiple security issues (b6587341-4d88-11e4-aef9-20cf30e32f6d)

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote FreeBSD host is missing a security-related update.

Description :

Bugzilla Security Advisory Unauthorized Account Creation An attacker
creating a new Bugzilla account can override certain parameters when
finalizing the account creation that can lead to the user being
created with a different email address than originally requested. The
overridden login name could be automatically added to groups based on
the group's regular expression setting. Cross-Site Scripting During an
audit of the Bugzilla code base, several places were found where
cross-site scripting exploits could occur which could allow an
attacker to access sensitive information. Information Leak If a new
comment was marked private to the insider group, and a flag was set in
the same transaction, the comment would be visible to flag recipients
even if they were not in the insider group. Social Engineering Search
results can be exported as a CSV file which can then be imported into
external spreadsheet programs. Specially formatted field values can be
interpreted as formulas which can be executed and used to attack a
user's computer.

See also :

https://bugzilla.mozilla.org/show_bug.cgi?id=1074812
https://bugzilla.mozilla.org/show_bug.cgi?id=1075578
https://bugzilla.mozilla.org/show_bug.cgi?id=1064140
https://bugzilla.mozilla.org/show_bug.cgi?id=1054702
http://www.nessus.org/u?9b04cbab

Solution :

Update the affected package.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N)

Family: FreeBSD Local Security Checks

Nessus Plugin ID: 78071 ()

Bugtraq ID:

CVE ID: CVE-2014-1571
CVE-2014-1572
CVE-2014-1573

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now