CVE-2005-1563: Medium severity Bugzilla vulnerability
Published May 14, 2005
·Updated
Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products.
Affected Software
23 affected components
Bugzilla=2.16.8
Bugzilla=2.16.1
Bugzilla=2.16.2
Bugzilla=2.10
Bugzilla=2.16
Bugzilla=2.16.9
Bugzilla=2.14.2
Bugzilla=2.18.1
Bugzilla=2.14.3
Bugzilla=2.14.4
Bugzilla=2.19.1
Bugzilla=2.16.7
Bugzilla=2.16.4
Bugzilla=2.12
Bugzilla=2.16.3
Bugzilla=2.14.5
Bugzilla=2.18
Bugzilla=2.16.6
Bugzilla=2.14.1
Bugzilla=2.16.5
Bugzilla=2.14
Bugzilla=2.19.2
Bugzilla=2.16.10
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
May 14, 2005
CVE Published
04:00 AM
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1563?
CVE-2005-1563 is considered a medium severity vulnerability due to its ability to expose hidden product information.
2
How do I fix CVE-2005-1563?
To fix CVE-2005-1563, upgrade to Bugzilla version 2.19.3 or later.
3
Which versions of Bugzilla are affected by CVE-2005-1563?
CVE-2005-1563 affects Bugzilla versions 2.10 through 2.19.2.
4
What type of vulnerability is CVE-2005-1563?
CVE-2005-1563 is classified as an information disclosure vulnerability.
5
Can CVE-2005-1563 lead to further attacks?
Yes, if exploited, CVE-2005-1563 could allow attackers to gather intelligence on the application's structure, potentially leading to more targeted attacks.