First published: Thu Jun 03 2004(Updated: )
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.16.1 | |
Mozilla Bugzilla | =2.16.2 | |
Mozilla Bugzilla | =2.17.4 | |
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.17.1 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.14.2 | |
Mozilla Bugzilla | =2.14.3 | |
Mozilla Bugzilla | =2.14.4 | |
Mozilla Bugzilla | =2.12 | |
Mozilla Bugzilla | =2.14 | |
Mozilla Bugzilla | =2.8 | |
Mozilla Bugzilla | =2.17.3 | |
Mozilla Bugzilla | =2.14.5 | |
Mozilla Bugzilla | =2.4 | |
Mozilla Bugzilla | =2.6 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.16.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1046 has a moderate severity rating due to its potential to expose restricted component descriptions.
To fix CVE-2003-1046, upgrade Bugzilla to a version that includes the security patch addressing this vulnerability.
CVE-2003-1046 affects Bugzilla versions 2.10, 2.14, 2.16, 2.17.1, 2.17.3, and 2.17.4.
Yes, CVE-2003-1046 can be exploited remotely by unauthorized users to access restricted component information.
CVE-2003-1046 allows attackers to list component descriptions for products they should not have access to.