CVE Vulnerabilities

CVE-2009-3989

Published: Feb 03, 2010 | Modified: Oct 10, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
4 LOW
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.

Affected Software

Name Vendor Start Version End Version
Bugzilla Mozilla * 3.0.10 (including)
Bugzilla Mozilla 2.0 (including) 2.0 (including)
Bugzilla Mozilla 2.2 (including) 2.2 (including)
Bugzilla Mozilla 2.4 (including) 2.4 (including)
Bugzilla Mozilla 2.6 (including) 2.6 (including)
Bugzilla Mozilla 2.8 (including) 2.8 (including)
Bugzilla Mozilla 2.10 (including) 2.10 (including)
Bugzilla Mozilla 2.12 (including) 2.12 (including)
Bugzilla Mozilla 2.14 (including) 2.14 (including)
Bugzilla Mozilla 2.14.1 (including) 2.14.1 (including)
Bugzilla Mozilla 2.14.2 (including) 2.14.2 (including)
Bugzilla Mozilla 2.14.3 (including) 2.14.3 (including)
Bugzilla Mozilla 2.14.4 (including) 2.14.4 (including)
Bugzilla Mozilla 2.14.5 (including) 2.14.5 (including)
Bugzilla Mozilla 2.16 (including) 2.16 (including)
Bugzilla Mozilla 2.16-rc1 (including) 2.16-rc1 (including)
Bugzilla Mozilla 2.16-rc2 (including) 2.16-rc2 (including)
Bugzilla Mozilla 2.16.1 (including) 2.16.1 (including)
Bugzilla Mozilla 2.16.2 (including) 2.16.2 (including)
Bugzilla Mozilla 2.16.3 (including) 2.16.3 (including)
Bugzilla Mozilla 2.16.4 (including) 2.16.4 (including)
Bugzilla Mozilla 2.16.5 (including) 2.16.5 (including)
Bugzilla Mozilla 2.16.6 (including) 2.16.6 (including)
Bugzilla Mozilla 2.16.7 (including) 2.16.7 (including)
Bugzilla Mozilla 2.16.8 (including) 2.16.8 (including)
Bugzilla Mozilla 2.16.9 (including) 2.16.9 (including)
Bugzilla Mozilla 2.16.10 (including) 2.16.10 (including)
Bugzilla Mozilla 2.16.11 (including) 2.16.11 (including)
Bugzilla Mozilla 2.18 (including) 2.18 (including)
Bugzilla Mozilla 2.18-rc1 (including) 2.18-rc1 (including)
Bugzilla Mozilla 2.18-rc2 (including) 2.18-rc2 (including)
Bugzilla Mozilla 2.18-rc3 (including) 2.18-rc3 (including)
Bugzilla Mozilla 2.18.1 (including) 2.18.1 (including)
Bugzilla Mozilla 2.18.2 (including) 2.18.2 (including)
Bugzilla Mozilla 2.18.3 (including) 2.18.3 (including)
Bugzilla Mozilla 2.18.4 (including) 2.18.4 (including)
Bugzilla Mozilla 2.18.5 (including) 2.18.5 (including)
Bugzilla Mozilla 2.18.6 (including) 2.18.6 (including)
Bugzilla Mozilla 2.18.6+ (including) 2.18.6+ (including)
Bugzilla Mozilla 2.18.7 (including) 2.18.7 (including)
Bugzilla Mozilla 2.18.8 (including) 2.18.8 (including)
Bugzilla Mozilla 2.18.9 (including) 2.18.9 (including)
Bugzilla Mozilla 2.20 (including) 2.20 (including)
Bugzilla Mozilla 2.20-rc1 (including) 2.20-rc1 (including)
Bugzilla Mozilla 2.20-rc2 (including) 2.20-rc2 (including)
Bugzilla Mozilla 2.20.1 (including) 2.20.1 (including)
Bugzilla Mozilla 2.20.2 (including) 2.20.2 (including)
Bugzilla Mozilla 2.20.3 (including) 2.20.3 (including)
Bugzilla Mozilla 2.20.4 (including) 2.20.4 (including)
Bugzilla Mozilla 2.20.5 (including) 2.20.5 (including)
Bugzilla Mozilla 2.20.6 (including) 2.20.6 (including)
Bugzilla Mozilla 2.20.7 (including) 2.20.7 (including)
Bugzilla Mozilla 2.22 (including) 2.22 (including)
Bugzilla Mozilla 2.22-rc1 (including) 2.22-rc1 (including)
Bugzilla Mozilla 2.22.1 (including) 2.22.1 (including)
Bugzilla Mozilla 2.22.2 (including) 2.22.2 (including)
Bugzilla Mozilla 2.22.3 (including) 2.22.3 (including)
Bugzilla Mozilla 2.22.4 (including) 2.22.4 (including)
Bugzilla Mozilla 2.22.5 (including) 2.22.5 (including)
Bugzilla Mozilla 2.22.6 (including) 2.22.6 (including)
Bugzilla Mozilla 2.22.7 (including) 2.22.7 (including)
Bugzilla Mozilla 3.0.0 (including) 3.0.0 (including)
Bugzilla Mozilla 3.0.1 (including) 3.0.1 (including)
Bugzilla Mozilla 3.0.2 (including) 3.0.2 (including)
Bugzilla Mozilla 3.0.3 (including) 3.0.3 (including)
Bugzilla Mozilla 3.0.4 (including) 3.0.4 (including)
Bugzilla Mozilla 3.0.5 (including) 3.0.5 (including)
Bugzilla Mozilla 3.0.6 (including) 3.0.6 (including)
Bugzilla Mozilla 3.0.7 (including) 3.0.7 (including)
Bugzilla Mozilla 3.0.8 (including) 3.0.8 (including)
Bugzilla Mozilla 3.0.9 (including) 3.0.9 (including)
Bugzilla Mozilla 3.2 (including) 3.2 (including)
Bugzilla Mozilla 3.2.1 (including) 3.2.1 (including)
Bugzilla Mozilla 3.2.2 (including) 3.2.2 (including)
Bugzilla Mozilla 3.2.3 (including) 3.2.3 (including)
Bugzilla Mozilla 3.2.4 (including) 3.2.4 (including)
Bugzilla Mozilla 3.2.5 (including) 3.2.5 (including)
Bugzilla Mozilla 3.4 (including) 3.4 (including)
Bugzilla Mozilla 3.4.1 (including) 3.4.1 (including)
Bugzilla Mozilla 3.4.2 (including) 3.4.2 (including)
Bugzilla Mozilla 3.4.3 (including) 3.4.3 (including)
Bugzilla Mozilla 3.4.4 (including) 3.4.4 (including)
Bugzilla Mozilla 3.5 (including) 3.5 (including)
Bugzilla Mozilla 3.5.1 (including) 3.5.1 (including)
Bugzilla Mozilla 3.5.2 (including) 3.5.2 (including)
Bugzilla Ubuntu dapper *
Bugzilla Ubuntu hardy *
Bugzilla Ubuntu intrepid *
Bugzilla Ubuntu jaunty *
Bugzilla Ubuntu karmic *
Bugzilla Ubuntu lucid *
Bugzilla Ubuntu upstream *

References