Bug 73166 - [PATCH] security fixed version - bugzill 2.16.7
Status: Closed FIXED
Product: Ports & Packages
Reported: 2004-10-26
Modified: 2004-10-27
Dmitry A Grigorovich 2004-10-26
See http://www.bugzilla.org/security/2.16.6/

Class:       Unauthorized Bug Change
Versions:    2.9 through 2.18rc2 and 2.19
Description: It is possible to send a carefully crafted HTTP POST
             message to process_bug.cgi which will remove keywords from
             a bug even if you don't have permissions to edit all bug
             fields (the "editbugs" permission).  Such changes are
             reported in "bug changed" email notifications, so they are
             easily detected and reversed if someone abuses it.
Reference:   https://bugzilla.mozilla.org/show_bug.cgi?id=252638

Fix: Apply patch
Reinstall bugzilla

PORTNAME?=     bugzilla
-PORTVERSION?=  2.16.6
+PORTVERSION?=  2.16.7
 CATEGORIES?=   devel
 MASTER_SITE_SUBDIR=    webtools webtools/archived
See http://www.bugzilla.org/security/2.16.6/
Pav Lucistnik 2004-10-27
State Changed
Committed, thanks!