Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bugzilla | Mozilla | 3.3.1 (including) | 3.3.1 (including) |
Bugzilla | Mozilla | 3.3.2 (including) | 3.3.2 (including) |
Bugzilla | Mozilla | 3.3.3 (including) | 3.3.3 (including) |
Bugzilla | Mozilla | 3.3.4 (including) | 3.3.4 (including) |
Bugzilla | Mozilla | 3.4 (including) | 3.4 (including) |
Bugzilla | Mozilla | 3.4.1 (including) | 3.4.1 (including) |
Bugzilla | Mozilla | 3.4.2 (including) | 3.4.2 (including) |
Bugzilla | Mozilla | 3.4.4 (including) | 3.4.4 (including) |
Bugzilla | Mozilla | 3.5.1 (including) | 3.5.1 (including) |
Bugzilla | Mozilla | 3.5.2 (including) | 3.5.2 (including) |
Bugzilla | Ubuntu | dapper | * |
Bugzilla | Ubuntu | hardy | * |
Bugzilla | Ubuntu | intrepid | * |
Bugzilla | Ubuntu | jaunty | * |
Bugzilla | Ubuntu | karmic | * |
Bugzilla | Ubuntu | lucid | * |
Bugzilla | Ubuntu | upstream | * |