CVE-2005-3139: Medium severity Bugzilla vulnerability
Published Oct 5, 2005
·Updated
Bugzilla 2.19.1 through 2.20rc2 and 2.21, with user matching turned on in substring mode, allows attackers to list all users whose names match an arbitrary substring, even when the usevisibilitygroups parameter is set.
Affected Software
6 affected components
Bugzilla=2.19.3
Bugzilla=2.20-rc2
Bugzilla=2.20-rc1
Bugzilla=2.19.1
Bugzilla=2.21
Bugzilla=2.19.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 5, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3139?
CVE-2005-3139 is considered a moderate severity vulnerability as it allows unauthorized user enumeration.
2
How do I fix CVE-2005-3139?
To fix CVE-2005-3139, upgrade to Bugzilla version 2.21 or later, where the vulnerability has been addressed.
3
Which versions of Bugzilla are affected by CVE-2005-3139?
CVE-2005-3139 affects Bugzilla versions 2.19.1 through 2.20rc2 and the version 2.21.
4
What is the impact of CVE-2005-3139?
The impact of CVE-2005-3139 is that attackers can list all users with matching names causing potential data leakage.
5
Is user matching turned on in substring mode related to CVE-2005-3139?
Yes, the vulnerability occurs specifically when user matching is turned on in substring mode.