Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 9: 2009-3405 Moderate Update to Address Bugzilla CSRF Vulnerability

fedora
Calendar Grey April 7, 2009
Dist Fedora Esm H88
Update 9 from Fed: addressed CSRF security flaw in Bugzilla bug tracker version 3.2.3 to bolster protection.
fix CVE-2009-1213

Summary

Bugzilla is a popular bug tracking system used by multiple open source projects

It requires a database engine installed - either MySQL, PostgreSQL or Oracle.

Without one of these database engines (local or remote), Bugzilla will not work

- see the Release Notes for details.

* Mon Apr 6 2009 Itamar Reis Peixoto 3.2.3-1

- fix CVE-2009-1213

* Thu Mar 5 2009 Itamar Reis Peixoto 3.2.2-2

- fix from BZ #474250 Comment #16, from Chris Eveleigh -->

- add python BR for contrib subpackage

- fix description

- change Requires perl-SOAP-Lite to perl(SOAP::Lite) according guidelines

* Sun Mar 1 2009 Itamar Reis Peixoto 3.2.2-1

- thanks to Chris Eveleigh

- for contributing with patches :-)

- Upgrade to upstream 3.2.2 to fix multiple security vulns

- Removed old perl_requires exclusions, added new ones for RADIUS, Oracle and sanitycheck.cgi

- Added Oracle to supported DBs in description (and moved line breaks)

- Include a patch to fix max_allowed_packet warnin when using with mysql

* Sat Feb 28 2009 Itamar Reis Peixoto 3.0.8-1

- Upgrade to 3.0.8, fix #466077 #438080

- fix macro in changelog rpmlint warning

- fix files-attr-not-set rpmlint warning for doc and contrib sub-packages

* Mon Feb 23 2009 Fedora Release Engineering - 3.0.4-4

- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild

* Mon Feb 2 2009 Stepan Kasal - 3.0.4-3

- do not require perl-Email-Simple, it is (no longer) in use

- remove several explicit perl-* requires; the automatic dependencies

do handle them

* Mon Jul 14 2008 Tom "spot" Callaway - 3.0.4-2

- fix license tag

* Fri May 9 2008 John Berninger - 3.0.4-1

- Update to upstream 3.0.4 to fix multiple security vulns

- Change perms on /etc/bugzilla for bz 427981

* Sun May 4 2008 John Berninger - 3.0.3-0

- Update to upstream 3.0.3 - bz 444669

[ 1 ] Bug #494398 - CVE-2009-1213 bugzilla: CSRF vulnerability in attachment editing

https://bugzilla.redhat.com/show_bug.cgi?id=494398

su -c 'yum update bugzilla' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 9
Version: 3.2.3
Release: 1.fc9
Summary: Bug tracking system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here