Command Injection in Bugzilla and Fedora - CVE-2014-8630

 

Command Injection in Bugzilla and Fedora - CVE-2014-8630

Published: February 1, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40919
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-8630
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to read and manipulate data.

Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.


Affected software

Bugzilla
Fedora
bugzilla

How to mitigate CVE-2014-8630

Install update from vendor's website.

bugzilla - update to 4.4.8-1.fc21.1

External References

Related Security Bulletins