First published: Wed Jul 21 2004(Updated: )
DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.17.6 | |
Mozilla Bugzilla | =2.16.1 | |
Mozilla Bugzilla | =2.16.2 | |
Mozilla Bugzilla | =2.17.4 | |
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.17.1 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.14.2 | |
Mozilla Bugzilla | =2.14.3 | |
Mozilla Bugzilla | =2.14.4 | |
Mozilla Bugzilla | =2.6 | |
Mozilla Bugzilla | =2.17.5 | |
Mozilla Bugzilla | =2.17.3 | |
Mozilla Bugzilla | =2.4 | |
Mozilla Bugzilla | =2.16.4 | |
Mozilla Bugzilla | =2.12 | |
Mozilla Bugzilla | =2.8 | |
Mozilla Bugzilla | =2.16.3 | |
Mozilla Bugzilla | =2.14.5 | |
Mozilla Bugzilla | =2.17.7 | |
Mozilla Bugzilla | =2.17 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.16.5 | |
Mozilla Bugzilla | =2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0702 is considered a medium severity vulnerability due to its potential for exposing sensitive database information.
To fix CVE-2004-0702, upgrade to a patched version of Bugzilla that is not vulnerable to this issue.
CVE-2004-0702 affects Bugzilla versions 2.17.1 through 2.17.7, as well as several earlier versions.
CVE-2004-0702 can expose the database password in error messages if the SQL server is not running.
A possible workaround for CVE-2004-0702 is to configure error handling to prevent sensitive information from being displayed in error messages.