CVE-2003-1045: Medium severity Bugzilla vulnerability
Published Jun 3, 2004
·Updated
votes.cgi in Bugzilla 2.16.3 and earlier, and 2.17.1 through 2.17.4, allows remote attackers to read a user's voting page when that user has voted on a restricted bug, which allows remote attackers to read potentially sensitive voting information by modifying the who parameter.
Affected Software
18 affected components
Bugzilla=2.4
Bugzilla=2.6
Bugzilla=2.8
Bugzilla=2.10
Bugzilla=2.12
Bugzilla=2.14
Bugzilla=2.14.1
Bugzilla=2.14.2
Bugzilla=2.14.3
Bugzilla=2.14.4
Bugzilla=2.14.5
Bugzilla=2.16
Bugzilla=2.16.1
Bugzilla=2.16.2
Bugzilla=2.16.3
Bugzilla=2.17.1
Bugzilla=2.17.3
Bugzilla=2.17.4
Remediation
Patch Available
Patch Available
Event History
Jun 3, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1045?
CVE-2003-1045 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2003-1045?
To fix CVE-2003-1045, upgrade Bugzilla to a version later than 2.17.4.
3
What are the affected versions for CVE-2003-1045?
CVE-2003-1045 affects Bugzilla versions 2.16.3 and earlier, as well as versions 2.17.1 through 2.17.4.
4
What impact does CVE-2003-1045 have on users?
CVE-2003-1045 allows remote attackers to read sensitive voting information from a user's voting page.
5
Is CVE-2003-1045 a remote vulnerability?
Yes, CVE-2003-1045 is a remote vulnerability that can be exploited over a network.