CVE-2010-0180

Publication date 28 June 2010

Last updated 24 July 2024


Ubuntu priority

Description

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.

Read the notes from the security team

Status

Package Ubuntu Release Status
bugzilla 10.04 LTS lucid
Not affected
9.10 karmic
Not affected
9.04 jaunty
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper
Not affected

Notes


mdeslaur

only affects 3.5+


Access our resources on patching vulnerabilities