Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora: 2009-3410 Critical Update for Bugzilla CSRF Vulnerability Fix

fedora
Calendar Grey April 7, 2009
Dist Fedora Esm H88
Important patch for Bugzilla on Fedora addressing CSRF vulnerabilities. Safeguard your systems with this essential update.
fix CVE-2009-1213

Summary

Bugzilla is a popular bug tracking system used by multiple open source projects

It requires a database engine installed - either MySQL, PostgreSQL or Oracle.

Without one of these database engines (local or remote), Bugzilla will not work

- see the Release Notes for details.

* Mon Apr 6 2009 Itamar Reis Peixoto 3.2.3-1

- fix CVE-2009-1213

* Thu Mar 5 2009 Itamar Reis Peixoto 3.2.2-2

- fix from BZ #474250 Comment #16, from Chris Eveleigh -->

- add python BR for contrib subpackage

- fix description

- change Requires perl-SOAP-Lite to perl(SOAP::Lite) according guidelines

* Sun Mar 1 2009 Itamar Reis Peixoto 3.2.2-1

- thanks to Chris Eveleigh

- for contributing with patches :-)

- Upgrade to upstream 3.2.2 to fix multiple security vulns

- Removed old perl_requires exclusions, added new ones for RADIUS, Oracle and sanitycheck.cgi

- Added Oracle to supported DBs in description (and moved line breaks)

- Include a patch to fix max_allowed_packet warnin when using with mysql

* Sat Feb 28 2009 Itamar Reis Peixoto 3.0.8-1

- Upgrade to 3.0.8, fix #466077 #438080

- fix macro in changelog rpmlint warning

- fix files-attr-not-set rpmlint warning for doc and contrib sub-packages

* Mon Feb 23 2009 Fedora Release Engineering - 3.0.4-4

- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

* Mon Feb 2 2009 Stepan Kasal - 3.0.4-3

- do not require perl-Email-Simple, it is (no longer) in use

- remove several explicit perl-* requires; the automatic dependencies

do handle them

[ 1 ] Bug #494398 - CVE-2009-1213 bugzilla: CSRF vulnerability in attachment editing

https://bugzilla.redhat.com/show_bug.cgi?id=494398

su -c 'yum update bugzilla' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 10
Version: 3.2.3
Release: 1.fc10
Summary: Bug tracking system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here