PT-2005-2542 · Mozilla · Bugzilla

Frédéric Buclin

+1

·

Published

2005-05-14

·

Updated

2016-10-18

·

CVE-2005-1563

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bugzilla versions 2.10 through 2.18 Bugzilla version 2.19.1 Bugzilla version 2.19.2
Description The issue allows remote attackers to determine hidden products by exploiting a difference in error messages displayed by the software, depending on whether a product exists or not.
Recommendations For Bugzilla versions 2.10 through 2.18, update to a version that does not display different error messages based on product existence to prevent exploitation. For Bugzilla version 2.19.1, modify the error message handling to prevent disclosure of hidden products. For Bugzilla version 2.19.2, adjust the product existence check to return a uniform error message, preventing attackers from determining hidden products.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1563

Affected Products

Bugzilla