Synced 30 Sept 2026 23:45 UTC Account
← All products

CVE-2001-1405

LOW severity · CVSS 2.1
2.1CVSS LOW

Summary

Bugzilla before 2.14 does not restrict access to sanitycheck.cgi, which allows local users to cause a denial of service (CPU consumption) via a flood of requests to sanitycheck.cgi.

Impact & exploitability

Attack vectorLocal
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)0%

AV:L/AC:L/Au:N/C:N/I:N/A:P

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: http://www.redhat.com/support/errata/RHSA-2001-107.html ↗