In association with heise online

07 May 2008, 09:46

Vulnerabilities in bug tracking system Bugzilla fixed

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

The latest update to the widely distributed Bugzilla open source bug tracking system fixes multiple vulnerabilities. In a security advisory the development team report three security holes that could be exploited by attackers to carry out cross-site scripting attacks. These would allow the status of a bug to be changed without the required privileges or the reporter of a bug to be faked.

The bugs affect Bugzilla prior to versions 2.20.6, 2.22.4, 3.0.4 and 3.1.4. Source code packages and patches for specific version branches can be downloaded from the project website. Linux distributors should also be distributing updated packages shortly, which Bugzilla administrators should install as soon as possible.

See also:

(mba)

Print Version | Send by email | Permalink: http://h-online.com/-735109
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit