CVE-2001-1405
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/09/2001
Last modified:
20/11/2024
Description
Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.
Impact
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:mozilla:bugzilla:2.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:mozilla:bugzilla:2.6:*:*:*:*:*:*:* | ||
cpe:2.3:a:mozilla:bugzilla:2.8:*:*:*:*:*:*:* | ||
cpe:2.3:a:mozilla:bugzilla:2.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:mozilla:bugzilla:2.12:*:*:*:*:*:*:* | ||
cpe:2.3:a:mozilla:bugzilla:2.14:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://bugzilla.mozilla.org/show_bug.cgi?id=54556
- http://marc.info/?l=bugtraq&m=99912899900567
- http://www.redhat.com/support/errata/RHSA-2001-107.html
- http://bugzilla.mozilla.org/show_bug.cgi?id=54556
- http://marc.info/?l=bugtraq&m=99912899900567
- http://www.redhat.com/support/errata/RHSA-2001-107.html