CVE-2009-3989: Medium severity Bugzilla vulnerability
Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3989?
CVE-2009-3989 has a moderate severity rating due to the potential exposure of sensitive information.
How do I fix CVE-2009-3989?
To fix CVE-2009-3989, upgrade Bugzilla to version 3.0.11 or later, or any 3.2.x version 3.2.6 or later.
What versions of Bugzilla are affected by CVE-2009-3989?
CVE-2009-3989 affects Bugzilla versions prior to 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3.
What type of attack is possible with CVE-2009-3989?
CVE-2009-3989 allows remote attackers to obtain sensitive information through unauthorized file access requests.
Is CVE-2009-3989 a remote vulnerability?
Yes, CVE-2009-3989 is a remote vulnerability that can be exploited without physical access to the affected Bugzilla installations.