CVE-2013-0786: Infoleak
The Bugzilla::Search::buildsubselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0786?
CVE-2013-0786 has a medium severity rating as it allows remote attackers to discover private product names.
How do I fix CVE-2013-0786?
To fix CVE-2013-0786, upgrade Bugzilla to version 3.6.13, 3.7.x, or 4.0.10 or later.
What versions of Bugzilla are affected by CVE-2013-0786?
CVE-2013-0786 affects Bugzilla versions 2.x and 3.x before 3.6.13, as well as 3.7.x and 4.0.x before 4.0.10.
What types of attacks can exploit CVE-2013-0786?
An attacker can exploit CVE-2013-0786 by sending invalid product queries to obtain error messages that disclose private product names.
Is there a workaround for CVE-2013-0786?
There is no known workaround for CVE-2013-0786; upgrading to a fixed version is the recommended mitigation.