1.9

CVE-2010-2470

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files in these directories, a different vulnerability than CVE-2010-0180.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MozillaBugzilla Version3.5.1
MozillaBugzilla Version3.5.2
MozillaBugzilla Version3.5.3
MozillaBugzilla Version3.6
MozillaBugzilla Version3.6 Updaterc1
MozillaBugzilla Version3.6.1
MozillaBugzilla Version3.7
MozillaBugzilla Version3.7.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 1.9 3.4 2.9
AV:L/AC:M/Au:N/C:P/I:N/A:N