First published: Tue Aug 09 2011(Updated: )
Bugzilla 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files. NOTE: this issue exists because of a regression in 3.6.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =3.6.0 | |
Mozilla Bugzilla | =3.6.1 | |
Mozilla Bugzilla | =3.6.2 | |
Mozilla Bugzilla | =3.6.3 | |
Mozilla Bugzilla | =3.6.4 | |
Mozilla Bugzilla | =3.6.5 | |
Mozilla Bugzilla | =3.7 | |
Mozilla Bugzilla | =3.7.1 | |
Mozilla Bugzilla | =3.7.2 | |
Mozilla Bugzilla | =3.7.3 | |
Mozilla Bugzilla | =4.0 | |
Mozilla Bugzilla | =4.0-rc1 | |
Mozilla Bugzilla | =4.0-rc2 | |
Mozilla Bugzilla | =4.0.1 | |
Mozilla Bugzilla | =4.1 | |
Mozilla Bugzilla | =4.1.1 | |
Mozilla Bugzilla | =4.1.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-2977 is considered a moderate severity vulnerability as it allows local users to access sensitive information.
To fix CVE-2011-2977, update Bugzilla to versions 3.6.6, 3.7.4, 4.0.2, or 4.1.3 or later.
CVE-2011-2977 affects users of Bugzilla versions 3.6.x prior to 3.6.6, 3.7.x, 4.0.x prior to 4.0.2, and 4.1.x prior to 4.1.3 on Windows.
CVE-2011-2977 is a local information disclosure vulnerability due to improper handling of temporary files.
CVE-2011-2977 was reported in 2011 and is associated with versions of Bugzilla prior to their respective patch releases.