---
title: "CVE-2005-3138\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2005-3138?format=md
keywords: index, follow
---

# CVE-2005-3138

Publication date 5 October 2005

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Bugzilla 2.18rc1 through 2.18.3, 2.19 through 2.20rc2, and 2.21 allows
remote attackers to obtain sensitive information such as the list of
installed products via the config.cgi file, which is accessible even when
the requirelogin parameter is set.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| bugzilla | 7.10 gutsy | Not affected |
| 7.04 feisty | Not affected |
| 6.10 edgy | Not affected |
| 6.06 LTS dapper | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-3138)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2005-3138)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2005-3138)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2005-3138)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2005-3138>
