LWN.net Logo

bugzilla: information leak

Package(s):bugzilla CVE #(s):CVE-2012-1969
Created:August 13, 2012 Updated:September 5, 2012
Description: From the CVE entry:

The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment description within a public comment, which allows remote attackers to obtain sensitive description information by reading a comment.

Alerts:
Fedora FEDORA-2012-11364 2012-08-13
Fedora FEDORA-2012-11324 2012-08-13
Mageia MGASA-2012-0255 2012-09-04
Mandriva MDVSA-2013:066 2013-04-08
Mageia MGASA-2013-0117 2013-04-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds