Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <4821F827.8010305@gentoo.org>
Date: Wed, 07 May 2008 20:42:47 +0200
From: Christian Hoffmann <hoffie@...too.org>
To: coley@...re.org
CC: oss-security@...ts.openwall.com
Subject: CVE request: Bugzilla (Unauthorized Bug Change, XSS, Account Impersonation)

Hi,

can we please get CVE ids assigned for the three issues mentioned in the 
release announcement [1] of the new bugzilla versions?

"""
* Users without the "canconfirm" privilege could enter a bug as
   NEW or ASSIGNED by using the XML-RPC interface.

* When viewing several bugs at once, there was a Cross-Site
   Scripting hole.

* The inbound email interface allowed you to set the Reporter via
   the text of the email, instead of just using the From header.
"""

[1] http://www.bugzilla.org/security/2.20.5/


Thanks,
-- 
Christian Hoffmann


Download attachment "signature.asc" of type "application/pgp-signature" (261 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.