Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-2979
Description:Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote attackers to determine the existence of private group names via a custom search. NOTE: this vulnerability exists because of a CVE-2010-2756 regression.
Test IDs: 1.3.6.1.4.1.25623.1.0.70264   1.3.6.1.4.1.25623.1.0.70411  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-2979
BugTraq ID: 49042
http://www.securityfocus.com/bid/49042
Debian Security Information: DSA-2322 (Google Search)
http://www.debian.org/security/2011/dsa-2322
http://www.osvdb.org/74298
http://www.osvdb.org/74299
http://secunia.com/advisories/45501
XForce ISS Database: bugzilla-queries-info-disclosure(69166)
https://exchange.xforce.ibmcloud.com/vulnerabilities/69166




© 1998-2025 E-Soft Inc. All rights reserved.