Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 10: Bugzilla 3.2.5-1 Critical: SQL Injection Threats

fedora
Calendar Grey September 18, 2009
Dist Fedora Esm H88
Upgrade to Bugzilla version 3.2.5 on Fedora 10 addresses vulnerabilities related to SQL injection, significantly improving the security for tracking software issues.
Update to upstream version 3.2.5 fixing two SQL injection security flaws (CVE-2009-3125, CVE-2009-3165) detailed in the upstream security advisory: https://www.bugzilla.org/securi...

Summary

Bugzilla is a popular bug tracking system used by multiple open source projects

It requires a database engine installed - either MySQL, PostgreSQL or Oracle.

Without one of these database engines (local or remote), Bugzilla will not work

- see the Release Notes for details.

Update Information:

Update to upstream version 3.2.5 fixing two SQL injection security flaws (CVE-2009-3125, CVE-2009-3165) detailed in the upstream security advisory: https://www.bugzilla.org/security/3.0.8/

Change Log

* Fri Sep 11 2009 Emmanuel Seyman - 3.2.5-1 - Update to 3.2.5 (CVE-2009-3125, CVE-2009-3165 and CVE-2009-3166) * Wed Jul 8 2009 Itamar Reis Peixoto - 3.2.4-1 - fix https://bugzilla.mozilla.org/show_bug.cgi?id=495257 * Mon Apr 6 2009 Itamar Reis Peixoto 3.2.3-1 - fix CVE-2009-1213 * Thu Mar 5 2009 Itamar Reis Peixoto 3.2.2-2 - fix from BZ #474250 Comment #16, from Chris Eveleigh --> - add python BR for contrib subpackage - fix description - change Requires perl-SOAP-Lite to perl(SOAP::Lite) according guidelines * Sun Mar 1 2009 Itamar Reis Peixoto 3.2.2-1 - thanks to Chris Eveleigh - for contributing with patches :-) - Upgrade to upstream 3.2.2 to fix multiple security vulns - Removed old perl_requires exclusions, added new ones for RADIUS, Oracle and sanitycheck.cgi - Added Oracle to supported DBs in description (and moved line breaks) - Include a patch to fix max_allowed_packet warnin when using with mysql * Sat Feb 28 2009 Itamar Reis Peixoto 3.0.8-1 - Upgrade to 3.0.8, fix #466077 #438080 - fix macro in changelog rpmlint warning - fix files-attr-not-set rpmlint warning for doc and contrib sub-packages * Mon Feb 23 2009 Fedora Release Engineering - 3.0.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Mon Feb 2 2009 Stepan Kasal - 3.0.4-3 - do not require perl-Email-Simple, it is (no longer) in use - remove several explicit perl-* requires; the automatic dependencies do handle them

References


[ 1 ] Bug #522547 - "major security issue" bugfix release imminent https://bugzilla.redhat.com/show_bug.cgi?id=522547

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update bugzilla' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: bugzilla
Product: Fedora 10
Version: 3.2.5
Release: 1.fc10
Summary: Bug tracking system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here