CVE-2004-0702

NameCVE-2004-0702
DescriptionDBI in Bugzilla 2.17.1 through 2.17.7 displays the database password in an error message when the SQL server is not running, which could allow remote attackers to gain sensitive information.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bugzillasourcewoody(not affected)
bugzillasourcesarge(not affected)
bugzillasource(unstable)2.18-1

Notes

[woody] - bugzilla <not-affected> (Only 2.17.* versions are vulnerable)
[sarge] - bugzilla <not-affected> (Only 2.17.* versions are vulnerable)

Search for package or bug name: Reporting problems