English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Bugzilla Information Disclosure Weaknesses


Secunia ID

SA38443

CVE-ID

CVE-2009-3387, CVE-2009-3989

Release Date

01 Feb 2010

Criticality

Less Critical

Solution Status

Vendor Patch

Software

Bugzilla 3.x

Where

From remote

Impact
Exposure of sensitive information

Vulnerabilities where documents or credentials are leaked or can be revealed either locally or from remote.

Description

Some weaknesses have been reported in Bugzilla, which can lead to the disclosure of sensitive information.

1) Bugzilla does not restrict access to the "CVS/", "contrib/", "docs/en/xml/", and "t/" directories and the "old-params.txt" file, which may contain sensitive information.

Note: By default, these locations do not contain any sensitive information.

This weakness is reported in all versions prior to 3.0.11, 3.2.6, 3.4.5, and 3.5.3.

2) An error within the group restriction when moving restricted bugs from one product to another can lead to unrestricted bugs, if e.g. no group is used in both products and no other group restrictions apply.

This weakness is reported in versions 3.3.1 to 3.4.4, 3.5.1, and 3.5.2.

Solution

Update to version 3.0.11, 3.2.6, 3.4.5, or 3.5.3.
http://www.bugzilla.org/download/

Reported by

1) Joel Peshkin and Frédéric Buclin
2) Frédéric Buclin

Original Advisory

http://www.bugzilla.org/security/3.0.10/