Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Daniel Piddock

#53582de 53,632
1.9CVSS total
Vulnerabilidades · 1
PT-2010-1994
1.9
2010-06-28
Mozilla · Bugzilla · CVE-2010-0180
**Name of the Vulnerable Software and Affected Versions** Bugzilla versions 3.5.1 through 3.7 **Description** The issue allows local users to read sensitive configuration fields due to world-readable permissions for the localconfig files when use suexec is enabled. This can be demonstrated by accessing the database password field and the site wide secret field. **Recommendations** For Bugzilla versions 3.5.1 through 3.7, consider changing the permissions of the localconfig files to prevent world-readable access when use suexec is enabled. As a temporary workaround, restrict access to the localconfig files to minimize the risk of exploitation.