CVE-2014-1571
published 2014-10-13CVE-2014-1571: Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users…
PriorityP417medium4CVSS 2.0
AVNACLAuSCPINAN
EPSS
1.35%
68.7th percentile
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to Bug.pm, Flag.pm, and a mail template.
Affected
187 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rcrm-4q59-vjfh: Bugzilla 2
ghsa_unreviewed·2022-05-17
CVE-2014-1571 [MEDIUM] CWE-200 GHSA-rcrm-4q59-vjfh: Bugzilla 2
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to Bug.pm, Flag.pm, and a mail template.
Red Hat
file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
vendor_redhat·2014-08-21·CVSS 6.5
CVE-2014-3587 [MEDIUM] CWE-190 file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
file: incomplete fix for CVE-2012-1571 in cdf_read_property_info
Integer overflow in the cdf_read_property_info function in cdf.c in file through 5.19, as used in the Fileinfo component in PHP before 5.4.32 and 5.5.x before 5.5.16, allows remote attackers to cause a denial of service (application crash) via a crafted CDF file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1571.
It was found that the fix for CVE-2012-1571 was incomplete; the File Information (fileinfo) extension did not correctly parse certain Composite Document Format (CDF) files. A remote attacker could use this flaw to crash a PHP application using fileinfo via a specially crafted CDF file.
Statement: This issue did not affect the php and the file packages as shipped with Red Hat Enterprise
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [fedora-all]
bugzilla·2014-10-07·CVSS 4.0
CVE-2014-1573 [MEDIUM] CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [fedora-all]
CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [epel-all]
bugzilla·2014-10-07·CVSS 4.0
CVE-2014-1573 [MEDIUM] CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [epel-all]
CVE-2014-1573 CVE-2014-1572 CVE-2014-1571 bugzilla: security fixes release [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2014-1571 CVE-2014-1572 CVE-2014-1573 bugzilla: security fixes release
bugzilla·2014-10-07·CVSS 4.0
CVE-2014-1571 [MEDIUM] CVE-2014-1571 CVE-2014-1572 CVE-2014-1573 bugzilla: security fixes release
CVE-2014-1571 CVE-2014-1572 CVE-2014-1573 bugzilla: security fixes release
Upstream has issued an advisory today (October 6):
http://www.bugzilla.org/security/4.0.14/
Class: Unauthorized Account Creation
Versions: 2.23.3 to 4.0.14, 4.1.1 to 4.2.10, 4.3.1 to 4.4.5, 4.5.1 to 4.5.5
Fixed In: 4.0.15, 4.2.11, 4.4.6, 4.5.6
Description: An attacker creating a new Bugzilla account can override certain
parameters when finalizing the account creation that can lead to the
user being created with a different email address than originally
requested. The overridden login name could be automatically added
to groups based on the group's regular expression setting.
References: https://bugzilla.mozilla.org/show_bug.cgi?id=1074812
CVE Number: CVE-2014-1572
Class: Cross-Site Scripting
Versions: 2.17.1 to 4
Bugzilla
[SECURITY] Private comments can be shown to flagmail recipients who aren't in the insider group
bugzilla·2014-09-08
[CRITICAL] [SECURITY] Private comments can be shown to flagmail recipients who aren't in the insider group
[SECURITY] Private comments can be shown to flagmail recipients who aren't in the insider group
template/en/default/email/flagmail.txt.tmpl has:
> [% IF Bugzilla.cgi.param("comment").defined && Bugzilla.cgi.param("comment").length > 0 %]
> ------- Additional Comments from [% user.identity %]
> [%+ Bugzilla.cgi.param("comment") FILTER strip_control_chars %]
it's highly likely this will not work for API driven updates.
Discussion:
Setting the security flag on this because of the follow situation:
User A is in the insider group. User B can see the bug, but is not in the insider group.
UserA make a private comment and sets the needinfo? flag, with User B as the requestee. User B receives the flag mail but it includes the private comment despite them not been able to see the private comm
http://advisories.mageia.org/MGASA-2014-0412.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-November/142524.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141309.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141321.htmlhttp://packetstormsecurity.com/files/128578/Bugzilla-Account-Creation-XSS-Information-Leak.htmlhttp://www.bugzilla.org/security/4.0.14/http://www.mandriva.com/security/advisories?name=MDVSA-2014:200http://www.securitytracker.com/id/1030978https://bugzilla.mozilla.org/show_bug.cgi?id=1064140http://advisories.mageia.org/MGASA-2014-0412.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-November/142524.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141309.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-October/141321.htmlhttp://packetstormsecurity.com/files/128578/Bugzilla-Account-Creation-XSS-Information-Leak.htmlhttp://www.bugzilla.org/security/4.0.14/http://www.mandriva.com/security/advisories?name=MDVSA-2014:200http://www.securitytracker.com/id/1030978https://bugzilla.mozilla.org/show_bug.cgi?id=1064140
2014-10-13
Published