Bug 149721 - [patch] port devel/bugzilla security update to 3.6.2
Summary: [patch] port devel/bugzilla security update to 3.6.2
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: skv
Depends on:
Reported: 2010-08-16 22:00 UTC by Olli Hauer
Modified: 2010-09-06 09:00 UTC (History)
1 user (show)

See Also:

patch_bugzilla.txt (1.13 KB, text/plain)
2010-08-16 22:00 UTC, Olli Hauer
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Olli Hauer freebsd_committer freebsd_triage 2010-08-16 22:00:10 UTC
Security update for bugzilla to versiopn 3.6.2.
(I'm running this verion now since a view days, no issues since
 now reported by the users)

Security Advisory
Source: http://www.bugzilla.org/security/3.2.7/ (5 Aug 2010)
* It was possible to (at least partially) determine the membership
  of any group using the Search interface.

* It was possible to use the 'sudo' feature without sending
  a notification to the user being impersonated.

* The 'Reports' and 'Duplicates' pages let you guess the name of
  products you could not see, due to the error message that was

* For installations using PostgreSQL, specifying "bug X" or
  "attachment X" in a comment would deny access to the bug if X was
  larger than the maximum 32-bit signed integer size.

All affected installations are encouraged to upgrade as soon as

Updates in this 3.6.x Release
Source: http://www.bugzilla.org/releases/3.6.2/release-notes.html
In addition, the following important fixes/changes have been made in
this release:

 * Email notifications where missing the dates that comments were 
   made. (Bug 578003)

 * Putting a phrase in quotes in the Quicksearch box now works properly,
   again. (Bug 578494 and Bug 553884)

 * Quicksearch was usually (incorrectly) being limited to 200 results.
   (Bug 581622)

 * Searching "keywords" for "contains none of the words" or "does not
   match regular expression" now works properly. (Bug 562014)

 * Doing collectstats.pl --regenerate now works on installations using
   PostgreSQL. (Bug 577058)

 * The "Field Values" administrative control panel was sometimes denying
   admins the ability to delete field values when there was no reason to
   deny the deletion. (Bug 577054)

 * Eliminate the "uninitialized value" warnings that would happen when
   editing a product's components. (Bug 576911)

 * The updating of bugs_fulltext that happens during checksetup.pl for
   upgrades to 3.6 should now be MUCH faster. (Bug 577754)

 * email_in.pl was not allowing the setting of time-tracking fields via
   inbound emails. (Bug 583622)
Comment 1 Edwin Groothuis freebsd_committer freebsd_triage 2010-08-16 22:00:54 UTC
Responsible Changed
From-To: freebsd-ports-bugs->skv

Over to maintainer (via the GNATS Auto Assign Tool)
Comment 2 skv freebsd_committer freebsd_triage 2010-08-24 17:28:57 UTC
State Changed
From-To: open->closed

Committed, thanks!
Comment 3 takatsu.tomonari 2010-09-04 07:51:18 UTC
Hi skv@,

It seems that bugzilla 3.6.2 had not been committed yet.
Please make sure your "cvs commit" operation.

TAKATSU Tomonari
Comment 4 dfilter service freebsd_committer freebsd_triage 2010-09-06 08:58:38 UTC
skv         2010-09-06 07:58:29 UTC

  FreeBSD ports repository

  Modified files:
    devel/bugzilla       Makefile distinfo 
  Update to 3.6.2
  Changes:        http://www.bugzilla.org/releases/3.6.2/release-notes.html
  Security:       http://www.vuxml.org/freebsd/8cbf4d65-af9a-11df-89b8-00151735203a.html
  PR:             ports/149721
  Submitted by:   ohauer
  Revision  Changes    Path
  1.78      +1 -1      ports/devel/bugzilla/Makefile
  1.41      +3 -3      ports/devel/bugzilla/distinfo
cvs-all@freebsd.org mailing list
To unsubscribe, send any mail to "cvs-all-unsubscribe@freebsd.org"