CVE-2010-0180: Low severity Bugzilla vulnerability
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when usesuexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the sitewidesecret field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0180?
CVE-2010-0180 has a medium severity rating due to the potential exposure of sensitive configuration information.
How do I fix CVE-2010-0180?
To fix CVE-2010-0180, ensure that localconfig files have restricted permissions to prevent unauthorized access.
Who is affected by CVE-2010-0180?
CVE-2010-0180 affects local users of Bugzilla versions 3.5.1 through 3.7 where use_suexec is enabled.
What information can be exposed by CVE-2010-0180?
CVE-2010-0180 can expose sensitive fields such as database passwords and site-wide secrets contained in localconfig files.
In which versions of Bugzilla is CVE-2010-0180 present?
CVE-2010-0180 is present in Bugzilla versions 3.5.1, 3.5.2, 3.5.3, 3.6, and 3.7.