Thinking OPEN

Posts Tagged ‘bugzilla’

Bugzilla 3.5.2 and prior [Medium]

By Security Team • Feb 3rd, 2010 • Category: Security Notifications

Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances….

CVE Identifier: CVE-2009-3387
Vulnerability Type(s):
Severity: Medium



Bugzilla 3.5.2 and prior [Medium]

By Security Team • Feb 3rd, 2010 • Category: Security Notifications

Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt….

CVE Identifier: CVE-2009-3989
Vulnerability Type(s):
Severity: Medium



Bugzilla 3.5.2 and prior [Medium]

By Security Team • Feb 3rd, 2010 • Category: Security Notifications

Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt….

CVE Identifier: CVE-2009-3989
Vulnerability Type(s):
Severity: Medium



Bugzilla 3.5.2 and prior [Medium]

By Security Team • Feb 3rd, 2010 • Category: Security Notifications

Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt….

CVE Identifier: CVE-2009-3989
Vulnerability Type(s):
Severity: Medium



Bugzilla 3.5.2 and prior [Medium]

By Security Team • Feb 3rd, 2010 • Category: Security Notifications

Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt….

CVE Identifier: CVE-2009-3989
Vulnerability Type(s):
Severity: Medium



Bugzilla 3.5.2 and prior [Medium]

By Security Team • Feb 3rd, 2010 • Category: Security Notifications

Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt….

CVE Identifier: CVE-2009-3989
Vulnerability Type(s):
Severity: Medium



Bugzilla 3.5.2 and prior [Medium]

By Security Team • Feb 3rd, 2010 • Category: Security Notifications

Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt….

CVE Identifier: CVE-2009-3989
Vulnerability Type(s):
Severity: Medium



Bugzilla 3.5.2 and prior [Medium]

By Security Team • Feb 3rd, 2010 • Category: Security Notifications

Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt….

CVE Identifier: CVE-2009-3989
Vulnerability Type(s):
Severity: Medium



Bugzilla 3.5.2 and prior [Medium]

By Security Team • Feb 3rd, 2010 • Category: Security Notifications

Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt….

CVE Identifier: CVE-2009-3989
Vulnerability Type(s):
Severity: Medium



Bugzilla 3.5.2 and prior [Medium]

By Security Team • Feb 3rd, 2010 • Category: Security Notifications

Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt….

CVE Identifier: CVE-2009-3989
Vulnerability Type(s):
Severity: Medium