LWN.net Logo

bugzilla: cross-site scripting

Package(s):bugzilla CVE #(s):CVE-2013-0785 CVE-2013-0786
Created:March 18, 2013 Updated:March 20, 2013
Description: From the Bugzilla advisory:

* When viewing a bug report, a bug ID containing random code is not correctly sanitized in the HTML page if the specified page format is invalid. This can lead to XSS.

* When running a query in debug mode, it is possible to determine if a given confidential field value (such as a product name) exists. Bugzilla 4.1 and newer are not affected by this issue.

Alerts:
Fedora FEDORA-2013-2866 2013-03-17
Fedora FEDORA-2013-2845 2013-03-17

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds