Bugzilla WebService (XML-RPC) interface information disclosure
| bugzilla-xmlrpc-information-disclosure (36244) |
Description:
Bugzilla could allow a remote attacker to obtain sensitive information, caused by insecure permissions on time-tracking fields in the WebService (XML-RPC) interface. An attacker could exploit this vulnerability to obtain sensitive information.
Platforms Affected:
- Gentoo, Linux
- Mozilla, Bugzilla 2.23.3
- Mozilla, Bugzilla 2.23.4
- Mozilla, Bugzilla 2.4
- Mozilla, Bugzilla 2.6
- Mozilla, Bugzilla 2.8
- Mozilla, Bugzilla 2.9
- Mozilla, Bugzilla 3.0.0
Remedy:
Refer to the Bugzilla Web site for patch, upgrade, or suggested workaround information. See References.
For Gentoo Linux (Bugzilla):
Refer to GLSA 200709-18 for patch, upgrade, or suggested workaround information. See References.
For other distributions:
Contact your vendor for upgrade or patch information.
Consequences:
Obtain Information
References:
- Bugzilla Web site, Bugzilla 2.20.4, 2.22.2, and 3.0 Security Advisory at http://www.bugzilla.org/security/2.20.4/.
- BID-25425: Bugzilla Multiple Remote Vulnerabilities
- CVE-2007-4539: The WebService (XML-RPC) interface in Bugzilla 2.23.3 through 3.0.0 does not enforce permissions for the time-tracking fields of bugs, which allows remote attackers to obtain sensitive information via certain XML-RPC requests, as demonstrated by the (1) Deadline and (2) Estimated Time fields.
- FrSIRT/ADV-2007-2977: Bugzilla Multiple Parameter Cross Site Scripting and Command Injection Issues
- GLSA-200709-18: Bugzilla: Multiple vulnerabilities
- SA26584: Bugzilla Security Issue and Multiple Vulnerabilities
- SECTRACK ID: 1018604: Bugzilla Bugs Let Remote Users Inject Commands, Obtain Restricted Information, and Conduct Cross-Site Scripting Attacks
Reported:
Aug 23, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
