Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bugzilla | Mozilla | 2.4 | 2.4 |
Bugzilla | Mozilla | 2.6 | 2.6 |
Bugzilla | Mozilla | 2.8 | 2.8 |
Bugzilla | Mozilla | 2.10 | 2.10 |
Bugzilla | Mozilla | 2.12 | 2.12 |
Bugzilla | Mozilla | 2.14 | 2.14 |