CVE-2003-0013: High severity Bugzilla vulnerability
The default .htaccess scripts for Bugzilla 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3 do not include filenames for backup copies of the localconfig file that are made from editors such as vi and Emacs, which could allow remote attackers to obtain a database password by directly accessing the backup file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bugzillato a version that resolves this vulnerability.Fixed in 2.14.5 - Upgrade
Upgrade
Bugzillato a version that resolves this vulnerability.Fixed in 2.16.2 - Upgrade
Upgrade
Bugzillato a version that resolves this vulnerability.Fixed in 2.17.3
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0013?
CVE-2003-0013 is classified as a moderate severity vulnerability due to potential exposure of sensitive information.
How do I fix CVE-2003-0013?
To fix CVE-2003-0013, you should upgrade Bugzilla to version 2.14.5 or later, 2.16.2 or later, or 2.17.3 or later.
Which versions of Bugzilla are affected by CVE-2003-0013?
CVE-2003-0013 affects Bugzilla versions 2.14.x before 2.14.5, 2.16.x before 2.16.2, and 2.17.x before 2.17.3.
What types of files are potentially exposed in CVE-2003-0013?
CVE-2003-0013 potentially exposes backup copies of the localconfig file created by text editors.
Who can exploit CVE-2003-0013?
CVE-2003-0013 can be exploited by remote attackers who gain access to improperly protected sensitive files.