CVE-2002-0810

Bugzilla <2.14.2-2.16rc2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Bugzilla 2.14 before 2.14.2, and 2.16 before 2.16rc2, directs error messages from the syncshadowdb command to the HTML output, which could leak sensitive information, including plaintext passwords, if syncshadowdb fails.

References (7)

Core 7
Core References
Various Sources vendor-advisory x_refsource_freebsd
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SN-02:05.asc
Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-06/0054.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/6399
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=92263
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2002-109.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4964
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9306.php

Scores

EPSS 0.0120
EPSS Percentile 64.7%

Details

Status published
Products (3)
mozilla/bugzilla 2.14
mozilla/bugzilla 2.14.1
mozilla/bugzilla 2.16 (2 CPE variants)
Published Aug 12, 2002
Tracked Since Feb 18, 2026