CVE-2006-5454
Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote attackers to obtain (1) the description of arbitrary attachments by viewing the attachment in "diff" mode in attachment.cgi, and (2) the…
Does this matter?
Lower severity and a low EPSS score (1.96%). Track it; it rarely justifies an emergency change on its own.
Description
Bugzilla 2.18.x before 2.18.6, 2.20.x before 2.20.3, 2.22.x before 2.22.1, and 2.23.x before 2.23.3 allow remote attackers to obtain (1) the description of arbitrary attachments by viewing the attachment in "diff" mode in attachment.cgi, and (2) the deadline field by viewing the XML format of the bug in show_bug.cgi.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.96% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/bugzilla
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/22409
- http://secunia.com/advisories/22790
- http://security.gentoo.org/glsa/glsa-200611-04.xml
- http://securityreason.com/securityalert/1760
- http://securitytracker.com/id?1017064Patch
- http://www.bugzilla.org/security/2.18.5/
- http://www.osvdb.org/29546
- http://www.osvdb.org/29547
- http://www.securityfocus.com/archive/1/448777/100/100/threaded
- http://www.securityfocus.com/bid/20538
- http://www.vupen.com/english/advisories/2006/4035
- https://bugzilla.mozilla.org/show_bug.cgi?id=346086Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=346564Patch
- http://secunia.com/advisories/22409
- http://secunia.com/advisories/22790
- http://security.gentoo.org/glsa/glsa-200611-04.xml
- http://securityreason.com/securityalert/1760
- http://securitytracker.com/id?1017064Patch
- http://www.bugzilla.org/security/2.18.5/
- http://www.osvdb.org/29546
- http://www.osvdb.org/29547
- http://www.securityfocus.com/archive/1/448777/100/100/threaded
- http://www.securityfocus.com/bid/20538
- http://www.vupen.com/english/advisories/2006/4035
- https://bugzilla.mozilla.org/show_bug.cgi?id=346086Patch
- https://bugzilla.mozilla.org/show_bug.cgi?id=346564Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.