CVE-2010-3764: Infoleak
The Old Charts implementation in Bugzilla 2.12 through 3.2.8, 3.4.8, 3.6.2, 3.7.3, and 4.1 creates graph files with predictable names in graphs/, which allows remote attackers to obtain sensitive information via a modified URL.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3764?
CVE-2010-3764 is classified as a moderate severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2010-3764?
To remediate CVE-2010-3764, upgrade Bugzilla to a version prior to 3.2.8 or apply the appropriate patches provided by the vendor.
What versions of Bugzilla are affected by CVE-2010-3764?
CVE-2010-3764 affects Bugzilla versions 2.12 through 3.2.8, along with several other specific versions.
What type of vulnerability is CVE-2010-3764?
CVE-2010-3764 is a path traversal vulnerability that allows remote attackers to access sensitive graph files.
Can CVE-2010-3764 be exploited remotely?
Yes, CVE-2010-3764 can be exploited remotely if the attacker manipulates the URL to access sensitive graph files.