CVE Vulnerabilities

CVE-2012-1968

Published: Jul 30, 2012 | Modified: Oct 03, 2013
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Bugzilla 4.1.x and 4.2.x before 4.2.2 and 4.3.x before 4.3.2 uses bug-editor privileges instead of bugmail-recipient privileges during construction of HTML bugmail documents, which allows remote attackers to obtain sensitive description information by reading the tooltip portions of an HTML e-mail message.

Affected Software

Name Vendor Start Version End Version
Bugzilla Mozilla 4.1 (including) 4.1 (including)
Bugzilla Mozilla 4.1.1 (including) 4.1.1 (including)
Bugzilla Mozilla 4.1.2 (including) 4.1.2 (including)
Bugzilla Mozilla 4.1.3 (including) 4.1.3 (including)
Bugzilla Mozilla 4.2 (including) 4.2 (including)
Bugzilla Mozilla 4.2-rc1 (including) 4.2-rc1 (including)
Bugzilla Mozilla 4.2-rc2 (including) 4.2-rc2 (including)
Bugzilla Mozilla 4.2.1 (including) 4.2.1 (including)
Bugzilla Mozilla 4.3 (including) 4.3 (including)
Bugzilla Mozilla 4.3.1 (including) 4.3.1 (including)

References