PT-2010-4272 · Mozilla · Bugzilla

Frédéric Buclin

·

Publicado

2010-08-13

·

Atualizado

2010-09-08

·

CVE-2010-2758

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bugzilla versions 2.17.1 through 3.2.7 Bugzilla versions 3.3.1 through 3.4.7 Bugzilla versions 3.5.1 through 3.6.1 Bugzilla versions 3.7 through 3.7.2
Description The issue allows remote attackers to guess product names via unspecified use of the (1) Reports or (2) Duplicates page, due to different error messages being generated depending on whether a product exists.
Recommendations For versions 2.17.1 through 3.2.7, update to a version outside of this range to resolve the issue. For versions 3.3.1 through 3.4.7, update to a version outside of this range to resolve the issue. For versions 3.5.1 through 3.6.1, update to a version outside of this range to resolve the issue. For versions 3.7 through 3.7.2, update to a version outside of this range to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-2758

Produtos afetados

Bugzilla