CVE-2012-1969
published 2012-07-30CVE-2012-1969: The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.55%
72.6th percentile
The get_attachment_link function in Template.pm in Bugzilla 2.x and 3.x before 3.6.10, 3.7.x and 4.0.x before 4.0.7, 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2 does not check whether an attachment is private before presenting the attachment description within a public comment, which allows remote attackers to obtain sensitive description information by reading a comment.
Affected
155 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
| mozilla | bugzilla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0785 CVE-2013-0786 bugzilla: XSS and information leak flaws fixed in 3.6.13/4.0.10/4.2.5/4.4rc2
bugzilla·2013-02-21·CVSS 4.3
CVE-2013-0785 [MEDIUM] CVE-2013-0785 CVE-2013-0786 bugzilla: XSS and information leak flaws fixed in 3.6.13/4.0.10/4.2.5/4.4rc2
CVE-2013-0785 CVE-2013-0786 bugzilla: XSS and information leak flaws fixed in 3.6.13/4.0.10/4.2.5/4.4rc2
Two flaws were reported as fixed in upstream bugzilla [1]:
Vulnerability Details
Class: Cross-Site Scripting
Versions: 2.0 to 3.6.12, 3.7.1 to 4.0.9, 4.1.1 to 4.2.4,
4.3.1 to 4.4rc1
Fixed In: 3.6.13, 4.0.10, 4.2.5, 4.4rc2
Description: When viewing a single bug report, which is the default,
the bug ID is validated and rejected if it is invalid.
But when viewing several bug reports at once, which is
specified by the format=multiple parameter, invalid bug
IDs can go through and are sanitized in the HTML page
itself. But when an invalid page format is passed to the
CGI script, the wrong HTML page is called and data are not
correctly sanitized, which can lead to XSS.
References: https://b
Bugzilla
CVE-2012-1969 bugzilla: information leak (description of private attachments)
bugzilla·2012-07-27·CVSS 4.3
CVE-2012-1969 [MEDIUM] CVE-2012-1969 bugzilla: information leak (description of private attachments)
CVE-2012-1969 bugzilla: information leak (description of private attachments)
From the upstream advisory [1]:
Class: Information Leak
Versions: 2.17.5 to 3.6.9, 3.7.1 to 4.0.6, 4.1.1 to 4.2.1, 4.3.1
Fixed In: 3.6.10, 4.0.7, 4.2.2, 4.3.2
Description: The description of a private attachment could be visible
to a user who hasn't permissions to access this attachment
if the attachment ID is mentioned in a public comment in
a bug that the user can see.
References: https://bugzilla.mozilla.org/show_bug.cgi?id=777586
CVE Number: CVE-2012-1969
This issue would affect Bugzilla as provided by all versions of Fedora and EPEL.
Additionally, another flaw is noted in the same advisory (CVE-2012-1968: information leak via HTML bug mails), but that flaw only affects Bugzilla 4.1.1 and higher (which is
Bugzilla
CVE-2012-1969 bugzilla: information leak (description of private attachments) [epel-all]
bugzilla·2012-07-27·CVSS 4.3
CVE-2012-1969 [MEDIUM] CVE-2012-1969 bugzilla: information leak (description of private attachments) [epel-all]
CVE-2012-1969 bugzilla: information leak (description of private attachments) [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?t
Bugzilla
CVE-2012-1969 bugzilla: information leak (description of private attachments) [fedora-all]
bugzilla·2012-07-27·CVSS 4.3
CVE-2012-1969 [MEDIUM] CVE-2012-1969 bugzilla: information leak (description of private attachments) [fedora-all]
CVE-2012-1969 bugzilla: information leak (description of private attachments) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/
http://secunia.com/advisories/50040http://www.bugzilla.org/security/3.6.9/http://www.mandriva.com/security/advisories?name=MDVSA-2013:066https://bugzilla.mozilla.org/show_bug.cgi?id=777586http://secunia.com/advisories/50040http://www.bugzilla.org/security/3.6.9/http://www.mandriva.com/security/advisories?name=MDVSA-2013:066https://bugzilla.mozilla.org/show_bug.cgi?id=777586
2012-07-30
Published