The Bugzilla bug tracking system (versions prior to 2.14.4 or 2.16.1)
suffers from a number of vulnerablities, including one which could result
in remote command and SQL injection. An upgrade to 2.16.1 is recommended,
since the 2.14 branch will be unmaintained after the end of the year. See
the Bugzilla advisory for details.
Posted Oct 3, 2002 9:25 UTC (Thu) by gerv (subscriber, #3376)
[Link]
Note that the SQL injection vulnerability is 2.16 only - 2.14 administrators don't need to upgrade to fix that problem.
Of the other two "security" issues, one is in contributed and unsupported email gateway code, and the other is not a server compromise, but a "see bugs you shouldn't" compromise, and only affects installations with more than 47 product groups.