Bug 256021 (CVE-2007-4543) - CVE-2007-45{38,39,43} Multiple Bugzilla security issues
Summary: CVE-2007-45{38,39,43} Multiple Bugzilla security issues
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2007-4543
Product: Fedora
Classification: Fedora
Component: bugzilla
Version: 7
Hardware: All
OS: Linux
medium
urgent
Target Milestone: ---
Assignee: John Berninger
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 256461 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-08-27 09:27 UTC by Alexander Koenig
Modified: 2007-11-30 22:12 UTC (History)
1 user (show)

Fixed In Version: 3.0.1-0.fc7
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2007-08-27 21:53:35 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Alexander Koenig 2007-08-27 09:27:02 UTC
Description of problem:

The current version of bugzilla in f7 has three major security issues
as described in bugzilla.org's security advisory from 23rd of August:
http://www.bugzilla.org/security/2.20.4/

As the issues are pretty severe, we have currently disabled our local
bugzilla to protect our server from abuse.

Version-Release number of selected component (if applicable):

bugzilla-3.0-3.fc7

Additional info:

Related bugzilla bugs:

https://bugzilla.mozilla.org/show_bug.cgi?id=386942
https://bugzilla.mozilla.org/show_bug.cgi?id=386860
https://bugzilla.mozilla.org/show_bug.cgi?id=382056

Comment 1 John Berninger 2007-08-27 13:29:04 UTC
Updates for FC-6, EL-4, EL-5 built in plague.  update for F-7 built in Koji. 
Pushing F-7 update via Bodhi now.

Comment 2 Lubomir Kundrak 2007-08-27 15:25:35 UTC
*** Bug 256461 has been marked as a duplicate of this bug. ***

Comment 3 Fedora Update System 2007-08-27 21:53:17 UTC
bugzilla-3.0.1-0.fc7 has been pushed to the Fedora 7 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 4 Lubomir Kundrak 2007-08-28 09:55:51 UTC
CVE assigned identifiers CVE-2007-4543, CVE-2007-4539 and CVE-2007-4538 to these
issues.



Note You need to log in before you can comment on or make changes to this bug.