CVE-2006-5454
Summary
| CVE | CVE-2006-5454 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-10-23 17:07:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote attackers to obtain (1) the description of arbitrary attachments by viewing the attachment in "diff" mode in attachment.cgi, and (2) the deadline field by viewing the XML format of the bug in show_bug.cgi. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mozilla | Bugzilla | 2.18 | All | All | All |
| Application | Mozilla | Bugzilla | 2.18 | rc1 | All | All |
| Application | Mozilla | Bugzilla | 2.18 | rc2 | All | All |
| Application | Mozilla | Bugzilla | 2.18 | rc3 | All | All |
| Application | Mozilla | Bugzilla | 2.18.1 | All | All | All |
| Application | Mozilla | Bugzilla | 2.18.2 | All | All | All |
| Application | Mozilla | Bugzilla | 2.18.3 | All | All | All |
| Application | Mozilla | Bugzilla | 2.18.4 | All | All | All |
| Application | Mozilla | Bugzilla | 2.18.5 | All | All | All |
| Application | Mozilla | Bugzilla | 2.20 | All | All | All |
| Application | Mozilla | Bugzilla | 2.20 | rc1 | All | All |
| Application | Mozilla | Bugzilla | 2.20 | rc2 | All | All |
| Application | Mozilla | Bugzilla | 2.20.1 | All | All | All |
| Application | Mozilla | Bugzilla | 2.20.2 | All | All | All |
| Application | Mozilla | Bugzilla | 2.22 | All | All | All |
| Application | Mozilla | Bugzilla | 2.23 | All | All | All |
| Application | Mozilla | Bugzilla | 2.23.1 | All | All | All |
| Application | Mozilla | Bugzilla | 2.23.2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityTracker.com Archives - Bugzilla Discloses Attachment Description and 'Deadline' Field to Remote Users | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch |
| Gentoo update for bugzilla - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory for Bugzilla 2.18.5, 2.20.2, 2.22, and 2.23.2 - CXSecurity.com | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| www.osvdb.org/29546 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Bugzilla Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Mozilla Bugzilla Multiple Input Validation and Information disclosure Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| www.osvdb.org/29547 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| 2.18.5, 2.20.2, 2.22, and 2.23.2 Security Advisory :: Bugzilla :: bugzilla.org | af854a3a-2127-422b-91ae-364da2661108 | www.bugzilla.org | |
| 346086 – [SECURITY] attachment.cgi lets you view descriptions of private attachments even when you are not in the insidergroup | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Patch |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| 346564 – [SECURITY] timetracking deadline leaks in XML | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.mozilla.org | Patch |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Bugzilla: Multiple Vulnerabilities — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.