Infesting you with Virus News
 

News

Contributed by: Lauren Gerber
Date: July 20, 2009
Lauren Gerber
0
Vote
0

Don't Let The Bugzilla Vulnerability Bug You

 

More and more computer security vulnerabilities are occurring at an alarming rate. It is extremely important for all users to be aware of the relevant patches, updates and fixes which are being released. If you don't want all the security vulnerabilities on the internet to bug you then you need to take the necessary steps in order to rectify the problems. The latest vulnerability, that poses a threat of bugging the general online public, relates to a vulnerability that has been confirmed in Bugzilla.Bugzilla.gif

This vulnerability runs the risk of being exploited by vicious online attackers. If this vulnerability is exploited effectively it will enable online attackers to bypass security restrictions. If these security restrictions are bypassed then the risks are very high that your personal information will be accessed. Of course, once they have access to your personal information, the sky is literally their limit.

This vulnerability seems to have taken place due to an application, that is not adequately confirmed with regard to the "canconfirm" privilege. Online attackers could take advantage of this vulnerability to effectively change the confirmation status of the bug reports, without the permission of the user.

Bugzilla is a fantastic web based system that tracks bugs accurately. It is utilized by a vast amount of software projects and is compatible with the majority of operating systems with the inclusion of Windows 2000. Some of the files of Windows 2000 are:axnds.ocx, bhp004.dll, bhp014.dll, c_eucdb.dll as well as CHKUPGRD.BAT.

This vulnerability has been confirmed and validated in versions 3.1.1, 3.2.3, 3.3.1 as well as versions 3.3.4. The solution for this vulnerability which is clearly going to start bugging everyone if nothing is done about it, is for all users to apply the relevant patches. I would thus like to quote the following in conclusion:"The Internet is becoming the town square for the global village of tomorrow."Bill Gates

User Comments

David Miller July 31, 2009
There is no personal information disclosure. The entire thing is summed up in the sentence "Online attackers could take advantage of this vulnerability to effectively change the confirmation status of the bug reports, without the permission of the user." That's it. That's ALL they can do. The files you list also have nothing to do with Bugzilla. The entire second paragraph, and the last sentence of each of the last two paragraphs seemingly have nothing to do with the subject matter of the article.
Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

March 17, 2010
March 17, 2010
Found this list of godaddy domain name coupons, I got a domain for my dog - ha $6.91 Domain... more..
March 17, 2010
Three guys were having a beer in a bar in London. They were all relative newly-weds and they were talking... more..
more comments..
rss
Home > Computer Security > Don't Let The Bugzilla Vulnerability Bug You