Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-0180

Опубликовано: 28 июн. 2010
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 1.9

Описание

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.

РелизСтатусПримечание
dapper

not-affected

2.20-1
devel

not-affected

3.2.5.1-3
hardy

not-affected

2.22.1-2.2ubuntu1.8.04.1
jaunty

not-affected

3.2.0.1-1
karmic

not-affected

3.2.4.0-3ubuntu1
lucid

not-affected

3.2.5.1-2
upstream

released

3.8

Показывать по

Ссылки на источники

EPSS

Процентиль: 17%
0.00053
Низкий

1.9 Low

CVSS2

Связанные уязвимости

nvd
больше 15 лет назад

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.

debian
больше 15 лет назад

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_ ...

github
больше 3 лет назад

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.

EPSS

Процентиль: 17%
0.00053
Низкий

1.9 Low

CVSS2