CVE-2010-2470Mozilla Bugzilla vulnerability

4 documents4 sources
Severity
1.9LOWNVD
EPSS
0.0%
top 86.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 28
Latest updateMay 17

Description

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files in these directories, a different vulnerability than CVE-2010-0180.

CVSS vector

AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9

Affected Packages1 packages

NVDmozilla/bugzilla7 versions+6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j577-qqg2-fg9j: Install/Filesystem2022-05-17
CVEList
CVE-2010-2470: Install/Filesystem2010-06-28

💥Exploits & PoCs

1
Exploit-DB
Microsoft Office 2007 - MSPTLS Heap Index Integer Underflow (MS15-081)2015-08-21
CVE-2010-2470 — Mozilla Bugzilla vulnerability | cvebase