Unrated severityNVD Advisory· Published Jun 28, 2010· Updated Jun 16, 2026
CVE-2010-2470
CVE-2010-2470
Description
Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6.1 and 3.7 through 3.7.1, when use_suexec is enabled, uses world-readable permissions within (1) .bzr/ and (2) data/webdot/, which allows local users to obtain potentially sensitive data by reading files in these directories, a different vulnerability than CVE-2010-0180.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:mozilla:bugzilla:3.5.1:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:a:mozilla:bugzilla:3.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:3.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:3.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:3.6:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:3.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:3.6:rc1:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:3.7:*:*:*:*:*:*:*
- cpe:2.3:a:mozilla:bugzilla:3.7.1:*:*:*:*:*:*:*
- (no CPE)range: >=3.5.1 <=3.6.1, >=3.7 <=3.7.1
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.