PT-2010-4046 · Mozilla · Bugzilla

Max Kanat-Alexander

·

Published

2010-06-28

·

Updated

2010-06-29

·

CVE-2010-2470

CVSS v2.0

1.9

Low

VectorAV:L/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Bugzilla versions 3.5.1 through 3.6.1 Bugzilla versions 3.7 through 3.7.1
Description The issue allows local users to obtain potentially sensitive data by reading files in certain directories. This occurs when the use suexec option is enabled. The affected directories include .bzr and data/webdot, which have world-readable permissions.
Recommendations For Bugzilla versions 3.5.1 through 3.6.1, consider changing the permissions of the .bzr and data/webdot directories to prevent world-readable access. For Bugzilla versions 3.7 through 3.7.1, consider changing the permissions of the .bzr and data/webdot directories to prevent world-readable access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2470

Affected Products

Bugzilla