Bugzilla Group Selection During Bug Move Information Disclosure Vulnerability
BID:38026
Info
Bugzilla Group Selection During Bug Move Information Disclosure Vulnerability
| Bugtraq ID: | 38026 |
| Class: | Access Validation Error |
| CVE: |
CVE-2009-3387 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 01 2010 12:00AM |
| Updated: | Apr 13 2015 08:26PM |
| Credit: | Frédéric Buclin |
| Vulnerable: |
Mozilla Bugzilla 3.5.2 Mozilla Bugzilla 3.5.1 Mozilla Bugzilla 3.4.4 Mozilla Bugzilla 3.4.3 Mozilla Bugzilla 3.4.2 Mozilla Bugzilla 3.4.1 Mozilla Bugzilla 3.3.4 Mozilla Bugzilla 3.3.3 Mozilla Bugzilla 3.3.2 Mozilla Bugzilla 3.3.1 Mozilla Bugzilla 3.4 rc1 Mozilla Bugzilla 3.4 Gentoo Linux |
| Not Vulnerable: |
Mozilla Bugzilla 3.5.3 Mozilla Bugzilla 3.4.5 |
Discussion
Bugzilla Group Selection During Bug Move Information Disclosure Vulnerability
Bugzilla is prone to an information-disclosure vulnerability.
Exploits may allow attackers to obtain potentially sensitive information that may aid in other attacks.
This issue affects the following:
Bugzilla 3.3.1 through 3.4.4
Bugzilla 3.5.1
Bugzilla 3.5.2
Bugzilla is prone to an information-disclosure vulnerability.
Exploits may allow attackers to obtain potentially sensitive information that may aid in other attacks.
This issue affects the following:
Bugzilla 3.3.1 through 3.4.4
Bugzilla 3.5.1
Bugzilla 3.5.2
Exploit / POC
Bugzilla Group Selection During Bug Move Information Disclosure Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
Bugzilla Group Selection During Bug Move Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Bugzilla Group Selection During Bug Move Information Disclosure Vulnerability
References:
References:
- Bug 532493 - (CVE-2009-3387) [SECURITY] Restricting a bug to a group while mov (Frédéric Buclin)
- Bugzilla Homepage (Mozilla)
- 3.0.10, 3.2.5, 3.4.4, and 3.5.2 Security Advisory (Mozilla)