Candidate: CVE-2010-2758 PublicDate: 2010-08-16 15:14:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2758 Description: Bugzilla 2.17.1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 generates different error messages depending on whether a product exists, which makes it easier for remote attackers to guess product names via unspecified use of the (1) Reports or (2) Duplicates page. Ubuntu-Description: Notes: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: Patches_bugzilla: upstream_bugzilla: released (3.7.3, 3.6.2, 3.4.8, 3.2.8) dapper_bugzilla: ignored (reached end-of-life) hardy_bugzilla: ignored (reached end-of-life) jaunty_bugzilla: ignored (reached end-of-life) karmic_bugzilla: ignored (reached end-of-life) lucid_bugzilla: ignored (reached end-of-life) maverick_bugzilla: not-affected (3.6.2.0-1) natty_bugzilla: not-affected (3.6.2.0-1) oneiric_bugzilla: not-affected (3.6.2.0-1) precise_bugzilla: DNE (dropped by debian) quantal_bugzilla: DNE (dropped by debian) raring_bugzilla: DNE (dropped by debian) saucy_bugzilla: DNE (dropped by debian) devel_bugzilla: DNE (dropped by debian)