Bugzilla remote command injection
2nd Oct 2002 [SBWID-5723]

	Bugzilla remote command injection


	All 2.14 and 2.16 releases up to 2.14.4 / 2.16.1


	In Bugzilla security advisory by Dave Miller :


	- Permissions leak when using "usebuggroups" and more  than  47  groups;
	permissions are granted to users in higher groups  when  they  shouldn't
	be.  (bug  167485;  comment   12   has   additional   detection/recovery


	-  calls   processmail   insecurely;   command
	injection possible. (bug 163024)

	The following additional security issue was fixed in 2.16.1:

	- Apostrophes are not properly  handled  during  account  creation;  SQL
	injection possible. (bug 165221)



	See Bugzilla branch 2.14.4 / 2.16.1

