LWN.net Logo

Multiple vulnerabilities in bugzilla

Multiple vulnerabilities in bugzilla

Posted Oct 3, 2002 9:25 UTC (Thu) by gerv (subscriber, #3376)
Parent article: Multiple vulnerabilities in bugzilla

Note that the SQL injection vulnerability is 2.16 only - 2.14 administrators don't need to upgrade to fix that problem.

Of the other two "security" issues, one is in contributed and unsupported email gateway code, and the other is not a server compromise, but a "see bugs you shouldn't" compromise, and only affects installations with more than 47 product groups.

Gerv


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds