First published: Mon Oct 25 2004(Updated: )
show_bug.cgi in Bugzilla 2.17.1 through 2.18rc2 and 2.19 from CVS, when using the insidergroup feature and exporting a bug to XML, shows comments and attachment summaries which are marked as private, which allows remote attackers to gain sensitive information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.17.6 | |
Mozilla Bugzilla | =2.16.1 | |
Mozilla Bugzilla | =2.18-rc1 | |
Mozilla Bugzilla | =2.16.2 | |
Mozilla Bugzilla | =2.17.4 | |
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.17.1 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.14.2 | |
Mozilla Bugzilla | =2.14.3 | |
Mozilla Bugzilla | =2.14.4 | |
Mozilla Bugzilla | =2.6 | |
Mozilla Bugzilla | =2.17.5 | |
Mozilla Bugzilla | =2.17.3 | |
Mozilla Bugzilla | =2.4 | |
Mozilla Bugzilla | =2.16.4 | |
Mozilla Bugzilla | =2.12 | |
Mozilla Bugzilla | =2.8 | |
Mozilla Bugzilla | =2.16.3 | |
Mozilla Bugzilla | =2.14.5 | |
Mozilla Bugzilla | =2.17.7 | |
Mozilla Bugzilla | =2.17 | |
Mozilla Bugzilla | =2.18-rc2 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.16.5 | |
Mozilla Bugzilla | =2.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1634 is classified as a medium severity vulnerability due to its potential to expose private comments and attachment summaries.
To fix CVE-2004-1634, upgrade to Bugzilla version 2.18 or later where this issue has been resolved.
CVE-2004-1634 affects Bugzilla versions 2.17.1 through 2.18rc2 and various earlier versions.
CVE-2004-1634 is an information disclosure vulnerability that allows remote attackers to access sensitive information.
Yes, CVE-2004-1634 can be exploited remotely, allowing attackers to retrieve private data without authentication.