LWN.net Logo

bugzilla: multiple vulnerabilities

Package(s):bugzilla CVE #(s):
Created:November 26, 2012 Updated:November 28, 2012
Description: From the Fedora advisory:

Update to 4.0.9

  • Confidential product and component names can be disclosed to unauthorized users if they are used to control the visibility of a custom field.
  • When calling the 'User.get' WebService method with a 'groups' argument, it is possible to check if the given group names exist or not.
  • Due to incorrectly filtered field values in tabular reports, it is possible to inject code which can lead to XSS.
  • When trying to mark an attachment in a bug you cannot see as obsolete, the description of the attachment is disclosed in the error message.
  • A vulnerability in swfstore.swf from YUI2 can lead to XSS.
Alerts:
Fedora FEDORA-2012-18210 2012-11-24
Fedora FEDORA-2012-18224 2012-11-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds