First published: Wed Oct 05 2005(Updated: )
Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.19.3 | |
Mozilla Bugzilla | =2.20-rc2 | |
Mozilla Bugzilla | =2.20-rc1 | |
Mozilla Bugzilla | =2.19.1 | |
Mozilla Bugzilla | =2.21 | |
Mozilla Bugzilla | =2.19.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3139 is considered a moderate severity vulnerability as it allows unauthorized user enumeration.
To fix CVE-2005-3139, upgrade to Bugzilla version 2.21 or later, where the vulnerability has been addressed.
CVE-2005-3139 affects Bugzilla versions 2.19.1 through 2.20rc2 and the version 2.21.
The impact of CVE-2005-3139 is that attackers can list all users with matching names causing potential data leakage.
Yes, the vulnerability occurs specifically when user matching is turned on in substring mode.