CVE-2010-2758: Infoleak
Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product names via unspecified use of the (1) Reports or (2) Duplicates page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2758?
CVE-2010-2758 is considered a moderate vulnerability due to its potential to aid attackers in guessing product names.
How do I fix CVE-2010-2758?
To mitigate CVE-2010-2758, upgrade to a version of Bugzilla that is not affected, specifically newer than 3.6.1.
What products are affected by CVE-2010-2758?
CVE-2010-2758 affects Bugzilla versions from 2.17.1 to 3.6.1 and includes specific versions leading up to 3.7.2.
Which Bugzilla versions should be upgraded to avoid CVE-2010-2758?
You should upgrade to Bugzilla version 3.7.3 or later to avoid CVE-2010-2758.
What type of attacks does CVE-2010-2758 facilitate?
CVE-2010-2758 facilitates enumeration attacks, allowing remote attackers to discover product names.