DBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Bugzilla | Mozilla | 2.4 (including) | 2.4 (including) |
| Bugzilla | Mozilla | 2.6 (including) | 2.6 (including) |
| Bugzilla | Mozilla | 2.8 (including) | 2.8 (including) |
| Bugzilla | Mozilla | 2.10 (including) | 2.10 (including) |
| Bugzilla | Mozilla | 2.12 (including) | 2.12 (including) |
| Bugzilla | Mozilla | 2.14 (including) | 2.14 (including) |
| Bugzilla | Mozilla | 2.14.1 (including) | 2.14.1 (including) |
| Bugzilla | Mozilla | 2.14.2 (including) | 2.14.2 (including) |
| Bugzilla | Mozilla | 2.14.3 (including) | 2.14.3 (including) |
| Bugzilla | Mozilla | 2.14.4 (including) | 2.14.4 (including) |
| Bugzilla | Mozilla | 2.14.5 (including) | 2.14.5 (including) |
| Bugzilla | Mozilla | 2.16 (including) | 2.16 (including) |
| Bugzilla | Mozilla | 2.16.1 (including) | 2.16.1 (including) |
| Bugzilla | Mozilla | 2.16.2 (including) | 2.16.2 (including) |
| Bugzilla | Mozilla | 2.16.3 (including) | 2.16.3 (including) |
| Bugzilla | Mozilla | 2.16.4 (including) | 2.16.4 (including) |
| Bugzilla | Mozilla | 2.16.5 (including) | 2.16.5 (including) |
| Bugzilla | Mozilla | 2.17 (including) | 2.17 (including) |
| Bugzilla | Mozilla | 2.17.1 (including) | 2.17.1 (including) |
| Bugzilla | Mozilla | 2.17.3 (including) | 2.17.3 (including) |
| Bugzilla | Mozilla | 2.17.4 (including) | 2.17.4 (including) |
| Bugzilla | Mozilla | 2.17.5 (including) | 2.17.5 (including) |
| Bugzilla | Mozilla | 2.17.6 (including) | 2.17.6 (including) |
| Bugzilla | Mozilla | 2.17.7 (including) | 2.17.7 (including) |