Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Order Openwall GNU/*/Linux 2.0 on a CD with delivery worldwide
[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Wed, 07 May 2008 20:42:47 +0200
From: Christian Hoffmann <hoffie@...too.org>
To: coley@...re.org
Subject: CVE request: Bugzilla (Unauthorized Bug Change, XSS, Account Impersonation)

Hi,

can we please get CVE ids assigned for the three issues mentioned in the 
release announcement [1] of the new bugzilla versions?

"""
* Users without the "canconfirm" privilege could enter a bug as
   NEW or ASSIGNED by using the XML-RPC interface.

* When viewing several bugs at once, there was a Cross-Site
   Scripting hole.

* The inbound email interface allowed you to set the Reporter via
   the text of the email, instead of just using the From header.
"""

[1] http://www.bugzilla.org/security/2.20.5/


Thanks,
-- 
Christian Hoffmann


[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux