First published: Tue Feb 06 2007(Updated: )
The mod_perl initialization script in Bugzilla 2.23.3 does not set the Bugzilla Apache configuration to allow .htaccess permissions to override file permissions, which allows remote attackers to obtain the database username and password via a direct request for the localconfig file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.23.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0792 is classified as a medium severity vulnerability.
CVE-2007-0792 allows remote attackers to access sensitive database credentials due to improper configuration of .htaccess permissions.
An attacker exploiting CVE-2007-0792 could gain unauthorized access to the database username and password.
To fix CVE-2007-0792, ensure that the Bugzilla Apache configuration allows .htaccess files to override permissions.
Yes, CVE-2007-0792 specifically affects Bugzilla version 2.23.3.