Lucene search

K
cveMitreCVE-2010-2757
HistoryAug 16, 2010 - 3:14 p.m.

CVE-2010-2757

2010-08-1615:14:12
CWE-310
mitre
web.nvd.nist.gov
29
cve-2010-2757
bugzilla
sudo
impersonation
remote authentication
security vulnerability

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0.003

Percentile

65.7%

The sudo feature in Bugzilla 2.22rc1 through 3.2.7, 3.3.1 through 3.4.7, 3.5.1 through 3.6.1, and 3.7 through 3.7.2 does not properly send impersonation notifications, which makes it easier for remote authenticated users to impersonate other users without discovery.

Affected configurations

Nvd
Node
mozillabugzillaMatch2.4
OR
mozillabugzillaMatch2.6
OR
mozillabugzillaMatch2.8
OR
mozillabugzillaMatch2.9
OR
mozillabugzillaMatch2.22
OR
mozillabugzillaMatch2.22rc1
OR
mozillabugzillaMatch2.22.1
OR
mozillabugzillaMatch2.22.3
OR
mozillabugzillaMatch2.22.4
OR
mozillabugzillaMatch2.22.5
OR
mozillabugzillaMatch2.22.6
OR
mozillabugzillaMatch2.22.7
OR
mozillabugzillaMatch2.23
OR
mozillabugzillaMatch2.23.1
OR
mozillabugzillaMatch2.23.2
OR
mozillabugzillaMatch2.23.3
OR
mozillabugzillaMatch2.23.4
OR
mozillabugzillaMatch3.0
OR
mozillabugzillaMatch3.0rc1
OR
mozillabugzillaMatch3.0.0
OR
mozillabugzillaMatch3.0.1
OR
mozillabugzillaMatch3.0.2
OR
mozillabugzillaMatch3.0.3
OR
mozillabugzillaMatch3.0.4
OR
mozillabugzillaMatch3.0.5
OR
mozillabugzillaMatch3.0.6
OR
mozillabugzillaMatch3.0.7
OR
mozillabugzillaMatch3.0.8
OR
mozillabugzillaMatch3.0.9
OR
mozillabugzillaMatch3.0.10
OR
mozillabugzillaMatch3.0.11
OR
mozillabugzillaMatch3.1.0
OR
mozillabugzillaMatch3.1.1
OR
mozillabugzillaMatch3.1.2
OR
mozillabugzillaMatch3.1.3
OR
mozillabugzillaMatch3.2
OR
mozillabugzillaMatch3.2.2
OR
mozillabugzillaMatch3.2.3
OR
mozillabugzillaMatch3.2.4
OR
mozillabugzillaMatch3.2.5
OR
mozillabugzillaMatch3.2.6
OR
mozillabugzillaMatch3.2.7
OR
mozillabugzillaMatch3.3.1
OR
mozillabugzillaMatch3.3.2
OR
mozillabugzillaMatch3.3.3
OR
mozillabugzillaMatch3.3.4
OR
mozillabugzillaMatch3.4.1
OR
mozillabugzillaMatch3.4.2
OR
mozillabugzillaMatch3.4.3
OR
mozillabugzillaMatch3.4.4
OR
mozillabugzillaMatch3.4.5
OR
mozillabugzillaMatch3.4.6
OR
mozillabugzillaMatch3.4.7
OR
mozillabugzillaMatch3.5.1
OR
mozillabugzillaMatch3.5.2
OR
mozillabugzillaMatch3.5.3
OR
mozillabugzillaMatch3.6
OR
mozillabugzillaMatch3.6.1
OR
mozillabugzillaMatch3.7
OR
mozillabugzillaMatch3.7.1
OR
mozillabugzillaMatch3.7.2
VendorProductVersionCPE
mozillabugzilla2.4cpe:2.3:a:mozilla:bugzilla:2.4:*:*:*:*:*:*:*
mozillabugzilla2.6cpe:2.3:a:mozilla:bugzilla:2.6:*:*:*:*:*:*:*
mozillabugzilla2.8cpe:2.3:a:mozilla:bugzilla:2.8:*:*:*:*:*:*:*
mozillabugzilla2.9cpe:2.3:a:mozilla:bugzilla:2.9:*:*:*:*:*:*:*
mozillabugzilla2.22cpe:2.3:a:mozilla:bugzilla:2.22:*:*:*:*:*:*:*
mozillabugzilla2.22cpe:2.3:a:mozilla:bugzilla:2.22:rc1:*:*:*:*:*:*
mozillabugzilla2.22.1cpe:2.3:a:mozilla:bugzilla:2.22.1:*:*:*:*:*:*:*
mozillabugzilla2.22.3cpe:2.3:a:mozilla:bugzilla:2.22.3:*:*:*:*:*:*:*
mozillabugzilla2.22.4cpe:2.3:a:mozilla:bugzilla:2.22.4:*:*:*:*:*:*:*
mozillabugzilla2.22.5cpe:2.3:a:mozilla:bugzilla:2.22.5:*:*:*:*:*:*:*
Rows per page:
1-10 of 611

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

AI Score

6

Confidence

Low

EPSS

0.003

Percentile

65.7%