Lucene search

K
ubuntucveUbuntu.comUB:CVE-2011-2979
HistoryAug 09, 2011 - 12:00 a.m.

CVE-2011-2979

2011-08-0900:00:00
ubuntu.com
ubuntu.com
16

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.032

Percentile

91.2%

Bugzilla 4.1.x before 4.1.3 generates different responses for certain
assignee queries depending on whether the group name is valid, which allows
remote attackers to determine the existence of private group names via a
custom search. NOTE: this vulnerability exists because of a CVE-2010-2756
regression.

Bugs

Notes

Author Note
mdeslaur 4.1.x only

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

EPSS

0.032

Percentile

91.2%