Fedora alert FEDORA-2010-10398 (bugzilla)
From: | updates@fedoraproject.org | |
To: | package-announce@lists.fedoraproject.org | |
Subject: | [SECURITY] Fedora 12 Update: bugzilla-3.4.7-1.fc12 | |
Date: | Mon, 05 Jul 2010 22:01:52 +0000 | |
Message-ID: | <20100705220152.AF6961115D2@bastion02.phx2.fedoraproject.org> | |
Archive‑link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2010-10398 2010-06-25 17:05:49 -------------------------------------------------------------------------------- Name : bugzilla Product : Fedora 12 Version : 3.4.7 Release : 1.fc12 URL : http://www.bugzilla.org/ Summary : Bug tracking system Description : Bugzilla is a popular bug tracking system used by multiple open source projects It requires a database engine installed - either MySQL, PostgreSQL or Oracle. Without one of these database engines (local or remote), Bugzilla will not work - see the Release Notes for details. -------------------------------------------------------------------------------- Update Information: The Bugzilla team has released v3.4.7 of their software, which fixes a remote information disclosure bug (users can search on time-tracking values even if they are not permitted to see them). See CVE-2010-1204 for all the gory details. -------------------------------------------------------------------------------- ChangeLog: * Fri Jun 25 2010 Emmanuel Seyman <emmanuel.seyman@club-internet.fr> - 3.4.7-1 - Update to 3.4.7 (CVE-2010-1204) * Mon Feb 1 2010 Emmanuel Seyman <emmanuel.seyman@club-internet.fr> - 3.4.5-1 - Update to 3.4.5 (CVE-2009-3989, CVE-2009-3387) - Remove bugzilla-EL5-perl-versions.patch which is EPEL-specific * Thu Nov 19 2009 Emmanuel Seyman <emmanuel.seyman@club-internet.fr> - 3.4.4-1 - Update to 3.4.4 (CVE-2009-3386) * Wed Nov 11 2009 Emmanuel Seyman <emmanuel.seyman@club-internet.fr> - 3.4.3-1 - Update to 3.4.3 (fixes memory leak issues) - Add perl(Digest::SHA) in the Requires - Specify Perl module versions in the Requires (fixes #524309) - Add an alias to make $webdotdir a working path (fixes #458848) -------------------------------------------------------------------------------- References: [ 1 ] Bug #608821 - CVE-2010-1204 Bugzilla: Sensitive time-tracking information disclosure via specially-crafted URL https://bugzilla.redhat.com/show_bug.cgi?id=608821 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update bugzilla' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...