Release date:
Updated on:
Affected Systems:
Mozilla Bugzilla 4.x
Mozilla Bugzilla 3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56504
Cve id: CVE-2012-4197
Bugzilla is an open-source defect tracking system that manages the entire lifecycle of defects in software development, such as submitting, repairing, and disabling defects.
Bugzilla tries to mark the attachments in the Bug invisible to the user as obsolete, and the Bug description will be leaked in the error message, resulting in information leakage.
<* Source: Frederic Buclin
Link: https://bugzilla.mozilla.org/show_bug.cgi? Id = 802204
Http://www.bugzilla.org/security/3.6.11/
Http://secunia.com/advisories/51265/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Mozilla
-------
The vendor has released patch 3.6.12, 4.0.9, 4.2.4, and 4.4rc1 to fix this security problem. Please download the patch from the vendor's homepage:
Http://www.mozilla.org/security/