PT-2010-4046 · Mozilla · Bugzilla

Max Kanat-Alexander

·

Publicado

2010-06-28

·

Atualizado

2010-06-29

·

CVE-2010-2470

CVSS v2.0

1.9

Baixa

VetorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bugzilla versions 3.5.1 through 3.6.1 Bugzilla versions 3.7 through 3.7.1
Description The issue allows local users to obtain potentially sensitive data by reading files in certain directories. This occurs when the use suexec option is enabled. The affected directories include .bzr and data/webdot, which have world-readable permissions.
Recommendations For Bugzilla versions 3.5.1 through 3.6.1, consider changing the permissions of the .bzr and data/webdot directories to prevent world-readable access. For Bugzilla versions 3.7 through 3.7.1, consider changing the permissions of the .bzr and data/webdot directories to prevent world-readable access.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2470

Produtos afetados

Bugzilla