CVE-2011-2979

Publication date 9 August 2011

Last updated 24 July 2024


Ubuntu priority

Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote attackers to determine the existence of private group names via a custom search. NOTE: this vulnerability exists because of a CVE-2010-2756 regression.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
bugzilla 11.04 natty
Not affected
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy
Not affected

Notes


mdeslaur

4.1.x only