CVE-2003-1046: High severity Bugzilla vulnerability
Published Jun 3, 2004
·Updated
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.
Affected Software
18 affected components
Bugzilla=2.4
Bugzilla=2.6
Bugzilla=2.8
Bugzilla=2.10
Bugzilla=2.12
Bugzilla=2.14
Bugzilla=2.14.1
Bugzilla=2.14.2
Bugzilla=2.14.3
Bugzilla=2.14.4
Bugzilla=2.14.5
Bugzilla=2.16
Bugzilla=2.16.1
Bugzilla=2.16.2
Bugzilla=2.16.3
Bugzilla=2.17.1
Bugzilla=2.17.3
Bugzilla=2.17.4
Remediation
Patch Available
Event History
Jun 3, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1046?
CVE-2003-1046 has a moderate severity rating due to its potential to expose restricted component descriptions.
2
How do I fix CVE-2003-1046?
To fix CVE-2003-1046, upgrade Bugzilla to a version that includes the security patch addressing this vulnerability.
3
What versions of Bugzilla are affected by CVE-2003-1046?
CVE-2003-1046 affects Bugzilla versions 2.10, 2.14, 2.16, 2.17.1, 2.17.3, and 2.17.4.
4
Can CVE-2003-1046 be exploited remotely?
Yes, CVE-2003-1046 can be exploited remotely by unauthorized users to access restricted component information.
5
What kind of access does CVE-2003-1046 allow?
CVE-2003-1046 allows attackers to list component descriptions for products they should not have access to.