FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2010-0180

This CVE name corresponds to:

Entered Topic
2010-07-05 bugzilla -- information disclosure

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2010-0180
Phase Assigned(20100106)

Description

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.

References

Source Reference
CONFIRM http://www.bugzilla.org/security/3.2.6/
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=561797
BID 41144
SECUNIA 40300
VUPEN ADV-2010-1595