---
title: "CVE-2011-2979\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-2979?format=md
keywords: index, follow
---

# CVE-2011-2979

Publication date 9 August 2011

Last updated 24 July 2024

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Bugzilla 4.1.x before 4.1.3 generates different responses for certain
assignee queries depending on whether the group name is valid, which allows
remote attackers to determine the existence of private group names via a
custom search. NOTE: this vulnerability exists because of a CVE-2010-2756
regression.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2011-2979?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| bugzilla | 11.04 natty | Not affected |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

4.1.x only

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2979)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-2979)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-2979)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-2979)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2011-2979>
