First published: Sat May 14 2005(Updated: )
Bugzilla 2.10 through 2.18, 2.19.1, and 2.19.2 displays a different error message depending on whether a product exists or not, which allows remote attackers to determine hidden products.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.16.8 | |
Mozilla Bugzilla | =2.16.1 | |
Mozilla Bugzilla | =2.16.2 | |
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.16.9 | |
Mozilla Bugzilla | =2.14.2 | |
Mozilla Bugzilla | =2.18.1 | |
Mozilla Bugzilla | =2.14.3 | |
Mozilla Bugzilla | =2.14.4 | |
Mozilla Bugzilla | =2.19.1 | |
Mozilla Bugzilla | =2.16.7 | |
Mozilla Bugzilla | =2.16.4 | |
Mozilla Bugzilla | =2.12 | |
Mozilla Bugzilla | =2.16.3 | |
Mozilla Bugzilla | =2.14.5 | |
Mozilla Bugzilla | =2.18 | |
Mozilla Bugzilla | =2.16.6 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.16.5 | |
Mozilla Bugzilla | =2.14 | |
Mozilla Bugzilla | =2.19.2 | |
Mozilla Bugzilla | =2.16.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1563 is considered a medium severity vulnerability due to its ability to expose hidden product information.
To fix CVE-2005-1563, upgrade to Bugzilla version 2.19.3 or later.
CVE-2005-1563 affects Bugzilla versions 2.10 through 2.19.2.
CVE-2005-1563 is classified as an information disclosure vulnerability.
Yes, if exploited, CVE-2005-1563 could allow attackers to gather intelligence on the application's structure, potentially leading to more targeted attacks.