mirror of
https://git.FreeBSD.org/ports.git
synced 2025-01-18 08:02:48 +00:00
Document "bugzilla" - information disclosure.
Feature safe: yes
This commit is contained in:
parent
d002884f35
commit
e6995fe802
Notes:
svn2git
2021-03-31 03:12:20 +00:00
svn path=/head/; revision=257407
@ -34,6 +34,49 @@ Note: Please add new entries to the beginning of this file.
|
||||
|
||||
-->
|
||||
<vuxml xmlns="http://www.vuxml.org/apps/vuxml-1">
|
||||
<vuln vid="f1331504-8849-11df-89b8-00151735203a">
|
||||
<topic>bugzilla -- information disclosure</topic>
|
||||
<affects>
|
||||
<package>
|
||||
<name>bugzilla</name>
|
||||
<range><gt>2.17.1</gt><lt>3.6.1</lt></range>
|
||||
</package>
|
||||
</affects>
|
||||
<description>
|
||||
<body xmlns="http://www.w3.org/1999/xhtml">
|
||||
<p>A Bugzilla Security Advisory reports:</p>
|
||||
<blockquote cite="http://www.bugzilla.org/security/3.2.6/">
|
||||
<ul>
|
||||
<li>Normally, information about time-tracking (estimated
|
||||
hours, actual hours, hours worked, and deadlines) is
|
||||
restricted to users in the "time-tracking group".
|
||||
However, any user was able, by crafting their own
|
||||
search URL, to search for bugs based using those
|
||||
fields as criteria, thus possibly exposing sensitive
|
||||
time-tracking information by a user seeing that a bug
|
||||
matched their search.</li>
|
||||
<li>If $use_suexec was set to "1" in the localconfig file,
|
||||
then the localconfig file's permissions were set as
|
||||
world-readable by checksetup.pl. This allowed any user
|
||||
with local shell access to see the contents of the file,
|
||||
including the database password and the site_wide_secret
|
||||
variable used for CSRF protection.</li>
|
||||
</ul>
|
||||
</blockquote>
|
||||
</body>
|
||||
</description>
|
||||
<references>
|
||||
<cvename>CVE-2010-1204</cvename>
|
||||
<cvename>CVE-2010-0180</cvename>
|
||||
<url>https://bugzilla.mozilla.org/show_bug.cgi?id=309952</url>
|
||||
<url>https://bugzilla.mozilla.org/show_bug.cgi?id=561797</url>
|
||||
</references>
|
||||
<dates>
|
||||
<discovery>2010-06-24</discovery>
|
||||
<entry>2010-07-05</entry>
|
||||
</dates>
|
||||
</vuln>
|
||||
|
||||
<vuln vid="8685d412-8468-11df-8d45-001d7d9eb79a">
|
||||
<topic>kvirc -- multiple vulnerabilities</topic>
|
||||
<affects>
|
||||
|
Loading…
Reference in New Issue
Block a user