Multiple vulnerabilities in bugzilla
Posted Oct 3, 2002 9:25 UTC (Thu) by
gerv (subscriber, #3376)
Parent article:
Multiple vulnerabilities in bugzilla
Note that the SQL injection vulnerability is 2.16 only - 2.14 administrators don't need to upgrade to fix that problem.
Of the other two "security" issues, one is in contributed and unsupported email gateway code, and the other is not a server compromise, but a "see bugs you shouldn't" compromise, and only affects installations with more than 47 product groups.
Gerv
(
Log in to post comments)