Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Fedora 26: 2018-b79f325c48 Moderate: Bugzilla CSRF Issue

fedora
Calendar Grey March 6, 2018
Dist Fedora Esm H88
Fedora 26 has released a security patch for Bugzilla addressing a CSRF vulnerability that potentially permits unauthorized access to sensitive report information.
A CSRF vulnerability in Bugzilla's report.cgi would allow a third-party site to extract confidential information from a bug the victim had access to

Summary

Bugzilla is a popular bug tracking system used by multiple open source projects

It requires a database engine installed - either MySQL, PostgreSQL or Oracle.

Without one of these database engines (local or remote), Bugzilla will not work

- see the Release Notes for details.

A CSRF vulnerability in Bugzilla's report.cgi would allow a third-party site to

extract confidential information from a bug the victim had access to. This

security bug has been published as CVE-2018-5123. This updates contains

Bugzilla 5.0.4, which fixes the issue.

[ 1 ] Bug #1438957 - icons are missing on bugzilla's front page

https://bugzilla.redhat.com/show_bug.cgi?id=1438957

su -c 'dnf upgrade bugzilla' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Product: Fedora 26
Version: 5.0.4
Release: 1.fc26
Summary: Bug tracking system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here