CVE-2003-1046
Bugzilla 2.17.3-2.17.4 - Unauthenticated Information Disclosure via describecomponents.cgi
Title source: llmDescription
describecomponents.cgi in Bugzilla 2.17.3 and 2.17.4 does not properly verify group membership when bug entry groups are used, which allows remote attackers to list component descriptions for otherwise restricted products.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/343185
Issue Tracking x_refsource_confirm
http://bugzilla.mozilla.org/show_bug.cgi?id=209742
Patch, Vendor Advisory vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/8953
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/13602
Scores
EPSS
0.0135
EPSS Percentile
68.4%
Details
Status
published
Products (18)
mozilla/bugzilla
2.4
mozilla/bugzilla
2.6
mozilla/bugzilla
2.8
mozilla/bugzilla
2.10
mozilla/bugzilla
2.12
mozilla/bugzilla
2.14
mozilla/bugzilla
2.14.1
mozilla/bugzilla
2.14.2
mozilla/bugzilla
2.14.3
mozilla/bugzilla
2.14.4
... and 8 more
Published
Aug 18, 2004
Tracked Since
Feb 18, 2026