PT-2005-2542 · Mozilla · Bugzilla

Frédéric Buclin

+1

·

Publicado

2005-05-14

·

Atualizado

2016-10-18

·

CVE-2005-1563

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bugzilla versions 2.10 through 2.18 Bugzilla version 2.19.1 Bugzilla version 2.19.2
Description The issue allows remote attackers to determine hidden products by exploiting a difference in error messages displayed by the software, depending on whether a product exists or not.
Recommendations For Bugzilla versions 2.10 through 2.18, update to a version that does not display different error messages based on product existence to prevent exploitation. For Bugzilla version 2.19.1, modify the error message handling to prevent disclosure of hidden products. For Bugzilla version 2.19.2, adjust the product existence check to return a uniform error message, preventing attackers from determining hidden products.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1563

Produtos afetados

Bugzilla