Total vulnerabilities in the database
Bugzilla 2.17.x, 2.18 before 2.18.2, 2.19.x, and 2.20 before 2.20rc1 inserts a bug into the database before it is marked private, which introduces a race condition and allows attackers to access information about the bug via buglist.cgi before MySQL replication is complete.
Software | From | Fixed in |
---|---|---|
mozilla / bugzilla | 2.17.6 | 2.17.6.x |
mozilla / bugzilla | 2.19.3 | 2.19.3.x |
mozilla / bugzilla | 2.19 | 2.19.x |
mozilla / bugzilla | 2.18-rc1 | 2.18-rc1.x |
mozilla / bugzilla | 2.17.4 | 2.17.4.x |
mozilla / bugzilla | 2.17.1 | 2.17.1.x |
mozilla / bugzilla | 2.18.1 | 2.18.1.x |
mozilla / bugzilla | 2.19.1 | 2.19.1.x |
mozilla / bugzilla | 2.17.5 | 2.17.5.x |
mozilla / bugzilla | 2.17.3 | 2.17.3.x |
mozilla / bugzilla | 2.18 | 2.18.x |
mozilla / bugzilla | 2.17.7 | 2.17.7.x |
mozilla / bugzilla | 2.18-rc3 | 2.18-rc3.x |
mozilla / bugzilla | 2.18-rc2 | 2.18-rc2.x |
mozilla / bugzilla | 2.19.2 | 2.19.2.x |