PT-2005-2542 · Mozilla · Bugzilla
Frédéric Buclin
+1
·
Published
2005-05-14
·
Updated
2016-10-18
·
CVE-2005-1563
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Bugzilla versions 2.10 through 2.18
Bugzilla version 2.19.1
Bugzilla version 2.19.2
Description
The issue allows remote attackers to determine hidden products by exploiting a difference in error messages displayed by the software, depending on whether a product exists or not.
Recommendations
For Bugzilla versions 2.10 through 2.18, update to a version that does not display different error messages based on product existence to prevent exploitation.
For Bugzilla version 2.19.1, modify the error message handling to prevent disclosure of hidden products.
For Bugzilla version 2.19.2, adjust the product existence check to return a uniform error message, preventing attackers from determining hidden products.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bugzilla