CVE-2010-0180
published 2010-06-28CVE-2010-0180: Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which…
PriorityP45low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.24%
14.7th percentile
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j577-qqg2-fg9j: Install/Filesystem
ghsa_unreviewed·2022-05-17·CVSS 1.9
CVE-2010-2470 [LOW] GHSA-j577-qqg2-fg9j: Install/Filesystem
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files in these directories, a different vulnerability than CVE-2010-0180.
GHSA
GHSA-7j23-jgvg-w62h: Install/Filesystem
ghsa_unreviewed·2022-05-02
CVE-2010-0180 [LOW] GHSA-7j23-jgvg-w62h: Install/Filesystem
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/40300http://www.bugzilla.org/security/3.2.6/http://www.securityfocus.com/bid/41144http://www.vupen.com/english/advisories/2010/1595https://bugzilla.mozilla.org/show_bug.cgi?id=561797http://secunia.com/advisories/40300http://www.bugzilla.org/security/3.2.6/http://www.securityfocus.com/bid/41144http://www.vupen.com/english/advisories/2010/1595https://bugzilla.mozilla.org/show_bug.cgi?id=561797
2010-06-28
Published