CVE Vulnerabilities

CVE-2002-0810

Published: Aug 12, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla2.14 (including)2.14 (including)
BugzillaMozilla2.14.1 (including)2.14.1 (including)
BugzillaMozilla2.16 (including)2.16 (including)
BugzillaMozilla2.16-rc1 (including)2.16-rc1 (including)
Red Hat Powertools 7.0RedHat*
Red Hat Powertools 7.1RedHat*

References