CVE-2014-8630

EUVD-2014-8467
Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 69%
Affected Products (NVD)
VendorProductVersion
mozillabugzilla
𝑥
≤ 4.0.16
mozillabugzilla
4.1
mozillabugzilla
4.1.1
mozillabugzilla
4.1.2
mozillabugzilla
4.1.3
mozillabugzilla
4.2
mozillabugzilla
4.2:rc1
mozillabugzilla
4.2:rc2
mozillabugzilla
4.2.1
mozillabugzilla
4.2.2
mozillabugzilla
4.2.3
mozillabugzilla
4.2.4
mozillabugzilla
4.2.5
mozillabugzilla
4.2.6
mozillabugzilla
4.2.7
mozillabugzilla
4.2.8
mozillabugzilla
4.2.9
mozillabugzilla
4.2.10
mozillabugzilla
4.2.11
mozillabugzilla
4.3
mozillabugzilla
4.3.1
mozillabugzilla
4.3.2
mozillabugzilla
4.3.3
mozillabugzilla
4.4
mozillabugzilla
4.4:rc1
mozillabugzilla
4.4:rc2
mozillabugzilla
4.4.1
mozillabugzilla
4.4.2
mozillabugzilla
4.4.3
mozillabugzilla
4.4.4
mozillabugzilla
4.4.5
mozillabugzilla
4.4.6
mozillabugzilla
4.5
mozillabugzilla
4.5.1
mozillabugzilla
4.5.2
mozillabugzilla
4.5.3
mozillabugzilla
4.5.4
mozillabugzilla
4.5.5
mozillabugzilla
4.5.6
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bugzilla
lucid
ignored
precise
dne
trusty
dne
utopic
dne
bugzilla4
lucid
dne
precise
dne
trusty
dne
utopic
dne