LWN.net Logo

bugzilla: information leak

Package(s):bugzilla CVE #(s):CVE-2009-3989 CVE-2009-3387
Created:February 9, 2010 Updated:June 4, 2010
Description: From the Bugzilla advisory:

This advisory covers two security issues that have recently been fixed in the Bugzilla code:

+ Some files stored on the web server are not correctly protected against external access and can be viewed from a web browser.

+ Restricting a bug to a group while moving the bug to another product has no effect if the group is not used by both products. The bug may become public if no other group restriction applies.

Alerts:
Gentoo 201006-19:02 2010-06-04
Fedora FEDORA-2010-1458 2010-02-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds