VYPR
Unrated severityNVD Advisory· Published Jun 28, 2010· Updated Jun 16, 2026

CVE-2010-2470

CVE-2010-2470

Description

Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files in these directories, a different vulnerability than CVE-2010-0180.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • cpe:2.3:a:mozilla:bugzilla:3.5.1:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:mozilla:bugzilla:3.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:3.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:3.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:3.6:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:3.6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:3.6:rc1:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:3.7:*:*:*:*:*:*:*
    • cpe:2.3:a:mozilla:bugzilla:3.7.1:*:*:*:*:*:*:*
    • (no CPE)range: >=3.5.1 <=3.6.1, >=3.7 <=3.7.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.