CVE-2010-2759: Medium severity Bugzilla vulnerability
Bugzilla 2.23.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2, when PostgreSQL is used, does not properly handle large integers in (1) bug and (2) attachment phrases, which allows remote authenticated users to cause a denial of service (bug invisibility) via a crafted comment.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2759?
CVE-2010-2759 has a medium severity rating due to potential denial of service vulnerabilities.
How do I fix CVE-2010-2759?
To fix CVE-2010-2759, you should upgrade to Bugzilla versions 3.2.7 or later, or apply the corresponding patches.
Which versions of Bugzilla are affected by CVE-2010-2759?
CVE-2010-2759 affects Bugzilla versions from 2.23.1 through 3.2.7 and 3.3.1 through 3.7.2.
What kind of attack does CVE-2010-2759 enable?
CVE-2010-2759 enables authenticated users to exploit the vulnerability to cause bug invisibility, leading to denial of service.
Who is primarily affected by CVE-2010-2759?
Organizations using implicated versions of Bugzilla with PostgreSQL are primarily affected by CVE-2010-2759.