CVE-2012-1968: Medium severity Bugzilla vulnerability
Published Jul 28, 2012
·Updated
Bugzilla 4.1.x and 4.2.x before 4.2.2 and 4.3.x before 4.3.2 uses bug-editor privileges instead of bugmail-recipient privileges during construction of HTML bugmail documents, which allows remote attackers to obtain sensitive description information by reading the tooltip portions of an HTML e-mail message.
Affected Software
10 affected components
Bugzilla=4.1
Bugzilla=4.1.1
Bugzilla=4.1.2
Bugzilla=4.1.3
Bugzilla=4.2
Bugzilla=4.2-rc1
Bugzilla=4.2-rc2
Bugzilla=4.2.1
Bugzilla=4.3
Bugzilla=4.3.1
Remediation
Patch Available
Event History
Jul 28, 2012
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-1968?
CVE-2012-1968 has been rated as a moderate severity vulnerability.
2
How do I fix CVE-2012-1968?
To fix CVE-2012-1968, upgrade Bugzilla to version 4.2.2 or 4.3.2 or later.
3
What versions of Bugzilla are affected by CVE-2012-1968?
CVE-2012-1968 affects Bugzilla versions 4.1.x and 4.2.x before 4.2.2, and 4.3.x before 4.3.2.
4
Can CVE-2012-1968 be exploited remotely?
Yes, CVE-2012-1968 can be exploited remotely to obtain sensitive information.
5
What is the nature of the vulnerability in CVE-2012-1968?
CVE-2012-1968 allows remote attackers to read sensitive parts of HTML bugmail documents due to improper privilege checks.