Bugzilla LocalConfig Backup File Disclosure Vulnerability
BID:6501
Info
Bugzilla LocalConfig Backup File Disclosure Vulnerability
| Bugtraq ID: | 6501 |
| Class: | Configuration Error |
| CVE: |
CVE-2003-0013 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 02 2003 12:00AM |
| Updated: | Jul 11 2009 07:17PM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
Mozilla Bugzilla 2.17.1 Mozilla Bugzilla 2.17 Mozilla Bugzilla 2.16.1 Mozilla Bugzilla 2.16 Mozilla Bugzilla 2.14.4 Mozilla Bugzilla 2.14.3 Mozilla Bugzilla 2.14.2 Mozilla Bugzilla 2.14.1 Mozilla Bugzilla 2.14 |
| Not Vulnerable: |
Mozilla Bugzilla 2.17.3 Mozilla Bugzilla 2.16.2 Mozilla Bugzilla 2.14.5 |
Discussion
Bugzilla LocalConfig Backup File Disclosure Vulnerability
Bugzilla is prone to a vulnerability that may result in backups of the localconfig file being disclosed to remote attackers.
The .htaccess files provided with the checksetup.pl script do not adequately protect backups of the localconfig file that may be created by text editors. As a result, it is possible for a remote user to request and gain unauthorized access to these backup files.
Bugzilla is prone to a vulnerability that may result in backups of the localconfig file being disclosed to remote attackers.
The .htaccess files provided with the checksetup.pl script do not adequately protect backups of the localconfig file that may be created by text editors. As a result, it is possible for a remote user to request and gain unauthorized access to these backup files.
Exploit / POC
Bugzilla LocalConfig Backup File Disclosure Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Bugzilla LocalConfig Backup File Disclosure Vulnerability
Solution:
Debian has released a security advisory (DSA 230-1) containing fixes. Users are advised to upgrade as soon as possible.
The vendor has addressed this issue in Bugzilla 2.14.5, 2.16.2 and 2.17.3. Patches for 2.14.4 and 2.16.1 have also been made available.
Mozilla Bugzilla 2.14
Mozilla Bugzilla 2.14.1
Mozilla Bugzilla 2.14.2
Mozilla Bugzilla 2.14.3
Mozilla Bugzilla 2.14.4
Mozilla Bugzilla 2.16
Mozilla Bugzilla 2.16.1
Mozilla Bugzilla 2.17
Mozilla Bugzilla 2.17.1
Solution:
Debian has released a security advisory (DSA 230-1) containing fixes. Users are advised to upgrade as soon as possible.
The vendor has addressed this issue in Bugzilla 2.14.5, 2.16.2 and 2.17.3. Patches for 2.14.4 and 2.16.1 have also been made available.
Mozilla Bugzilla 2.14
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.14.1
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.14.2
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html -
Debian bugzilla-doc_2.14.2-0woody4_all.deb
http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla-doc_2 .14.2-0woody4_all.deb -
Debian bugzilla_2.14.2-0woody4_all.deb
http://security.debian.org/pool/updates/main/b/bugzilla/bugzilla_2.14. 2-0woody4_all.deb
Mozilla Bugzilla 2.14.3
-
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.14.4
-
Bugzilla bugzilla-2.14.4-to-2.14.5.diff.gz
http://ftp.mozilla.org/pub/webtools/bugzilla-2.14.4-to-2.14.5.diff.gz -
Bugzilla Bugzilla 2.14.5
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.16
-
Bugzilla Bugzilla 2.16.2
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.16.1
-
Bugzilla bugzilla-2.16.1-to-2.16.2.diff.gz
http://ftp.mozilla.org/pub/webtools/bugzilla-2.16.1-to-2.16.2.diff.gz -
Bugzilla Bugzilla 2.16.2
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.17
-
Bugzilla Bugzilla 2.17.3
http://www.bugzilla.org/download.html
Mozilla Bugzilla 2.17.1
-
Bugzilla Bugzilla 2.17.3
http://www.bugzilla.org/download.html
References
Bugzilla LocalConfig Backup File Disclosure Vulnerability
References:
References:
- Bugzilla Homepage (Mozilla)
- [BUGZILLA] Security Advisory - remote database password disclosure (David Miller
)