Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 296520 (CVE-2009-3386) - <www-apps/bugzilla-3.4.4 Alias Field Information Leak (CVE-2009-3386)
Summary: <www-apps/bugzilla-3.4.4 Alias Field Information Leak (CVE-2009-3386)
Status: RESOLVED FIXED
Alias: CVE-2009-3386
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial (vote)
Assignee: Gentoo Security
URL: http://www.bugzilla.org/security/3.4.3/
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-12-11 13:36 UTC by Robert Buchholz (RETIRED)
Modified: 2010-05-31 07:17 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2009-12-11 13:36:21 UTC
* Aliases of hidden bugs would show up in the "Depends On" and "Blocks"
  list of other bugs, even if you didn't have permission to see the
  hidden bugs.

All affected installations are encouraged to upgrade as soon as
possible.

Vulnerability Details
=====================

Class:       Information Leak
Versions:    3.3.2 to 3.4.3, 3.5 to 3.5.1
Fixed In:    3.4.4, 3.5.2
Description: When a bug is in a group, none of its information
             (other than its status and resolution) should be visible
             to users outside that group. It was discovered that
             as of 3.3.2, Bugzilla was showing the alias of the bug 
             (a very short string used as a shortcut for looking up
             the bug) to users outside of the group, if the protected
             bug ended up in the "Depends On" or "Blocks" list of any
             other bug.
References:  https://bugzilla.mozilla.org/show_bug.cgi?id=529416
CVE Number:  CVE-2009-3386
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2009-12-11 13:38:24 UTC
Please bump our unstable to 3.4.4.
Comment 2 Stefan Behte (RETIRED) gentoo-dev Security 2009-12-18 01:29:14 UTC
CVE-2009-3386 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2009-3386):
  Template.pm in Bugzilla 3.3.2 through 3.4.3 and 3.5 through 3.5.1
  allows remote attackers to discover the alias of a private bug by
  reading the (1) Depends On or (2) Blocks field of a related bug.

Comment 3 Torsten Veller (RETIRED) gentoo-dev 2010-02-18 08:17:51 UTC
3.4.5 is in the tree (#303725)
Comment 4 Alex Legler (RETIRED) archtester gentoo-dev Security 2010-05-31 07:17:11 UTC
~arch issue only. Closing noglsa.