MGASA-2014-0412
Dashboard / Vulnerabilities / MGASA-2014-0412
MGASA-2014-0412
Summary: Updated bugzilla packages fix security vulnerabilities
Details: Updated bugzilla packages fix security vulnerabilities: If a new comment was marked private to the insider group, and a flag was set in the same transaction, the comment would be visible to flag recipients even if they were not in the insider group (CVE-2014-1571). An attacker creating a new Bugzilla account can override certain parameters when finalizing the account creation that can lead to the user being created with a different email address than originally requested. The overridden login name could be automatically added to groups based on the group's regular expression setting (CVE-2014-1572). During an audit of the Bugzilla code base, several places were found where cross-site scripting exploits could occur which could allow an attacker to access sensitive information (CVE-2014-1573).
References: https://advisories.mageia.org/MGASA-2014-0412.html, https://bugs.mageia.org/show_bug.cgi?id=14241, http://www.bugzilla.org/security/4.0.14/, http://www.bugzilla.org/releases/4.4.6/release-notes.html
Affected packages
Package
Name: bugzilla
Purl: pkg:rpm/mageia/bugzilla?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
