CVE Vulnerabilities

CVE-2011-2977

Published: Aug 09, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Bugzilla 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files. NOTE: this issue exists because of a regression in 3.6.

Affected Software

NameVendorStart VersionEnd Version
BugzillaMozilla3.6.0 (including)3.6.0 (including)
BugzillaMozilla3.6.1 (including)3.6.1 (including)
BugzillaMozilla3.6.2 (including)3.6.2 (including)
BugzillaMozilla3.6.3 (including)3.6.3 (including)
BugzillaMozilla3.6.4 (including)3.6.4 (including)
BugzillaMozilla3.6.5 (including)3.6.5 (including)
BugzillaMozilla3.7 (including)3.7 (including)
BugzillaMozilla3.7.1 (including)3.7.1 (including)
BugzillaMozilla3.7.2 (including)3.7.2 (including)
BugzillaMozilla3.7.3 (including)3.7.3 (including)
BugzillaMozilla4.0 (including)4.0 (including)
BugzillaMozilla4.0-rc1 (including)4.0-rc1 (including)
BugzillaMozilla4.0-rc2 (including)4.0-rc2 (including)
BugzillaMozilla4.0.1 (including)4.0.1 (including)
BugzillaMozilla4.1 (including)4.1 (including)
BugzillaMozilla4.1.1 (including)4.1.1 (including)
BugzillaMozilla4.1.2 (including)4.1.2 (including)
BugzillaUbuntuupstream*

References