Vulnerability Bulletins |
Ejecución de comandos arbitrarios en Bugzilla |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Experto |
| Required attacker level | Acceso remoto con cuenta |
System information |
|
| Property | Value |
| Affected manufacturer | GNU/Linux |
| Affected software |
Bugzilla < 3.0.8 Bugzilla 3.1.x < 3.2.4 Bugzilla 3.3.1 < 3.4.1 |
Description |
|
|
Se ha descubierto una vulnerabilidad de inyección SQL en Bugzilla. La vulnerabilidad reside en un error en la función Bug.create WebService. Un atacante remoto podría ejecutar comandos SQL arbitrarios mediante métodos no especificados. |
|
Solution |
|
|
Actualización de software Debian (DSA-1913-1) Debian Linux 5.0 Source http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla_3.0.4.1-2+lenny2.dsc http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla_3.0.4.1-2+lenny2.diff.gz http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla_3.0.4.1.orig.tar.gz Arquitectura independiente: http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla3_3.0.4.1-2+lenny2_all.deb http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla3-doc_3.0.4.1-2+lenny2_all.deb |
|
Standar resources |
|
| Property | Value |
| CVE | CVE-2009-3165 |
| BID | 36373 |
Other resources |
|
|
Debian Security Advisory (DSA-1913-1) http://lists.debian.org/debian-security-announce/2009/msg00235.html |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2009-10-19 |






