CVE-2007-4539
published 2007-08-27CVE-2007-4539: The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote…
PriorityP421medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.65%
74.1th percentile
The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-ppwq-7f2c-mmrh: The WebService (XML-RPC) interface in Bugzilla 2
ghsa_unreviewed·2022-05-01
CVE-2007-4539 [MEDIUM] GHSA-ppwq-7f2c-mmrh: The WebService (XML-RPC) interface in Bugzilla 2
The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.
Red Hat
kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
vendor_redhat·2008-10-29·CVSS 7.2
CVE-2008-4539 [HIGH] kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
No detection rules found.
Bugzilla
CVE-2008-4539 kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
bugzilla·2008-10-14·CVSS 7.2
CVE-2008-4539 [HIGH] CVE-2008-4539 kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
CVE-2008-4539 kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
Created attachment 320281
Proposed actualized upstream qemu patch to resolve the Cirrus LGD-54XX "bitblt" heap overflow (CVE-2007-1320)
Jan Niehusmann discovered that the upstream fix for the CVE-2007-1320 is
incomplete and still allows local users to cause a heap-based buffer overlow,
when connecting via the VNC console.
Steps to reproduce:
No reproducer.
Upstream qemu patch for the initial CVE-2007-1320 issue:
https://svn.pardus.org.tr/pardus/2007/applications/emulators/qemu/files/CVE-2007-1320.patch
Proposed upstream correction of this patch - see attachment.
Discussion:
QEMU upstream commit:
http://git.kernel.dk/?p=qemu.git;a=commitdiff;h=65d35a09979e63541afc5bfc595b9f1b1b4ae069
More on current status of thi
Bugzilla
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 8]
bugzilla·2008-05-27·CVSS 7.2
CVE-2007-1320 [HIGH] CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 8]
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 8]
kvm-60-6.fc8 has been submitted as an update for Fedora 8
Discussion:
*** This bug has been marked as a duplicate of 237342 ***
---
kvm-60-6.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
It appears this beast is still alive.
CVE-2008-4539 is its new name.
---
kvm-60-7.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/kvm-60-7.fc8
---
kvm-60-7.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 9]
bugzilla·2008-05-27·CVSS 7.2
CVE-2007-1320 [HIGH] CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 9]
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 9]
kvm-65-7.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
Discussion:
It appears this beast is still alive.
CVE-2008-4539 is its new name.
---
kvm-65-11.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/kvm-65-11.fc9
---
kvm-65-11.fc9 has been pushed to the Fedora 9 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can install it with
su -c 'yum --enablerepo=updates-testing update kvm'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F9/FEDORA-2008-9571
---
kvm-65-13.fc9 has been subm
http://osvdb.org/37202http://secunia.com/advisories/26584http://secunia.com/advisories/26971http://security.gentoo.org/glsa/glsa-200709-18.xmlhttp://www.bugzilla.org/security/2.20.4/http://www.securityfocus.com/archive/1/477630/100/0/threadedhttp://www.securityfocus.com/bid/25425http://www.securitytracker.com/id?1018604http://www.vupen.com/english/advisories/2007/2977https://bugzilla.mozilla.org/show_bug.cgi?id=382056https://exchange.xforce.ibmcloud.com/vulnerabilities/36244http://osvdb.org/37202http://secunia.com/advisories/26584http://secunia.com/advisories/26971http://security.gentoo.org/glsa/glsa-200709-18.xmlhttp://www.bugzilla.org/security/2.20.4/http://www.securityfocus.com/archive/1/477630/100/0/threadedhttp://www.securityfocus.com/bid/25425http://www.securitytracker.com/id?1018604http://www.vupen.com/english/advisories/2007/2977https://bugzilla.mozilla.org/show_bug.cgi?id=382056https://exchange.xforce.ibmcloud.com/vulnerabilities/36244
2007-08-27
Published