LWN.net Logo

bugzilla: multiple vulnerabilities

Package(s):bugzilla CVE #(s):CVE-2008-2103 CVE-2008-2105
Created:May 12, 2008 Updated:May 14, 2008
Description:

From the Red Hat bugzilla:

CVE-2008-2103: Cross-site scripting (XSS) vulnerability in Bugzilla 2.17.2 and later allows remote attackers to inject arbitrary web script or HTML via the id parameter to the "Format for Printing" view or "Long Format" bug list.

CVE-2008-2105: email_in.pl in Bugzilla 2.23.4, and later versions before 3.0, allows remote authenticated users to more easily spoof the changer of a bug via a @reporter command in the body of an e-mail message, which overrides the e-mail address as normally obtained from the From e-mail header. NOTE: since From headers are easily spoofed, this only crosses privilege boundaries in environments that provide additional verification of e-mail addresses.

Alerts:
Fedora FEDORA-2008-3488 2008-05-09
Fedora FEDORA-2008-3442 2008-05-09
Fedora FEDORA-2008-3668 2008-05-13

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.