| Vulnerability Name: | CVE-2009-3387 (CCN-56004) |
| Assigned: | 2009-09-24 |
| Published: | 2010-01-31 |
| Updated: | 2018-10-10 |
| Summary: | Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.
|
| CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)| Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | | Scope: | Scope (S): Unchanged
| | Impact Metrics: | Confidentiality (C): Low Integrity (I): None Availibility (A): None |
|
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)| Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N) 3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)| Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Medium Athentication (Au): None
| | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None |
|
| Vulnerability Type: | CWE-264
|
| Vulnerability Consequences: | Obtain Information |
| References: | Source: MITRE Type: CNA CVE-2009-3387
Source: CCN Type: SA38443 Bugzilla Information Disclosure Weaknesses
Source: SECUNIA Type: Vendor Advisory 38443
Source: CCN Type: Bugzilla Web site 3.0.10, 3.2.5, 3.4.4, and 3.5.2 Security Advisory
Source: CCN Type: GLSA-201006-19 Bugzilla: Multiple vulnerabilities
Source: CCN Type: OSVDB ID: 62148 Bugzilla Product Category Group Restriction Weakness Remote Information Disclosure
Source: BUGTRAQ Type: UNKNOWN 20100201 Security Advisory for Bugzilla 3.0.10, 3.2.5, 3.4.4, and 3.5.2
Source: CCN Type: BID-38025 Bugzilla Directory Access Information Disclosure Vulnerability
Source: BID Type: UNKNOWN 38026
Source: CCN Type: BID-38026 Bugzilla Group Selection During Bug Move Information Disclosure Vulnerability
Source: VUPEN Type: Patch, Vendor Advisory ADV-2010-0261
Source: CCN Type: Bugzilla@Mozilla Bug 532493 (CVE-2009-3387) [SECURITY] Restricting a bug to a group while moving it to another product has no effect if the group is not used by both products
Source: CONFIRM Type: UNKNOWN https://bugzilla.mozilla.org/show_bug.cgi?id=532493
Source: XF Type: UNKNOWN bugzilla-group-restriction-info-disclosure(56004)
Source: XF Type: UNKNOWN bugzilla-group-restriction-info-disclosure(56004)
|
| Vulnerable Configuration: | Configuration 1: cpe:/a:mozilla:bugzilla:3.3.1:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.3.2:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.3.3:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.3.4:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.4:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.4.1:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.4.2:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.4.4:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.5.1:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.5.2:*:*:*:*:*:*:* Configuration CCN 1: cpe:/a:mozilla:bugzilla:3.3.2:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.3.3:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.3.4:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.4:rc1:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.4:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.4.1:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.5:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.5.1:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.4.3:*:*:*:*:*:*:*OR cpe:/a:mozilla:bugzilla:3.4.2:*:*:*:*:*:*:*AND cpe:/o:gentoo:linux:*:*:*:*:*:*:*:*
Denotes that component is vulnerable |
| BACK |