Bug 159576 - devel/bugzilla: Security Advisory for Bugzilla Versions Prior to 3.6.6, 4.0.2
Summary: devel/bugzilla: Security Advisory for Bugzilla Versions Prior to 3.6.6, 4.0.2
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: skv
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2011-08-07 08:30 UTC by Peter
Modified: 2011-08-13 19:30 UTC (History)
0 users

See Also:


Attachments
devel_bugzilla-4.0.2-20110807-00.patch (934 bytes, patch)
2011-08-07 12:51 UTC, Peter
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Peter 2011-08-07 08:30:08 UTC
The following impacts the ports devel/bugzilla and devel/bugzilla3 at least:

* Internet Explorer 8 and older, and Safari before 5.0.6 do content
  sniffing when viewing a patch in "Raw Unified" mode, which could
  trigger a cross-site scripting attack due to the execution of
  malicious code in the attachment.

* Attachment descriptions with a newline in them could lead to the
  injection of crafted headers in email notifications sent to the
  requestee or the requester when editing an attachment flag.

* If an attacker has access to a user's session, he can modify that
  user's email address without that user being notified of the change.

===

References:  https://bugzilla.mozilla.org/show_bug.cgi?id=637981
CVE Number:  CVE-2011-2379

Class:       Information Leak
Comment 1 Peter 2011-08-07 12:51:01 UTC
You can't take no for an answer, FreeBSD-gnats-submit!

Attaching a patch here for devel/bugzilla it works for me that way.
devel/bugzilla3 still needs a patch.

73! Peter pgp: A0E26627 (4A42 6841 2871 5EA7 52AB  12F8 0CE1 4AAC A0E2 6627)
--
http://vereshagin.org
Comment 2 Tilman Keskinoz freebsd_committer freebsd_triage 2011-08-07 14:09:52 UTC
Responsible Changed
From-To: freebsd-ports-bugs->skv

over to maintainer
Comment 3 dfilter service freebsd_committer freebsd_triage 2011-08-13 19:24:30 UTC
skv         2011-08-13 18:24:21 UTC

  FreeBSD ports repository

  Modified files:
    devel/bugzilla       Makefile distinfo 
  Log:
  Update to 4.0.2
  
  Changes:        http://www.bugzilla.org/releases/4.0.2/release-notes.html
  Security:       http://www.vuxml.org/freebsd/dc8741b9-c5d5-11e0-8a8e-00151735203a.html
  PR:             ports/159576
  Submitted by:   Peter Vereshagin <peter@vereshagin.org>
  
  Revision  Changes    Path
  1.87      +3 -4      ports/devel/bugzilla/Makefile
  1.46      +2 -2      ports/devel/bugzilla/distinfo
_______________________________________________
cvs-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/cvs-all
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"
Comment 4 skv freebsd_committer freebsd_triage 2011-08-13 19:25:31 UTC
State Changed
From-To: open->closed

Committed, thanks!