bugzilla: information leak
| Package(s): | bugzilla | CVE #(s): | CVE-2009-3989 CVE-2009-3387 | ||||||||
| Created: | February 9, 2010 | Updated: | June 4, 2010 | ||||||||
| Description: | From the Bugzilla advisory:
This advisory covers two security issues that have recently been fixed in the Bugzilla code: + Some files stored on the web server are not correctly protected against external access and can be viewed from a web browser. + Restricting a bug to a group while moving the bug to another product has no effect if the group is not used by both products. The bug may become public if no other group restriction applies. | ||||||||||
| Alerts: |
| ||||||||||
