Vulnerabilities in bug tracking system Bugzilla fixed
The latest update to the widely distributed Bugzilla open source bug tracking system fixes multiple vulnerabilities. In a security advisory the development team report three security holes that could be exploited by attackers to carry out cross-site scripting attacks. These would allow the status of a bug to be changed without the required privileges or the reporter of a bug to be faked.
The bugs affect Bugzilla prior to versions 2.20.6, 2.22.4, 3.0.4 and 3.1.4. Source code packages and patches for specific version branches can be downloaded from the project website. Linux distributors should also be distributing updated packages shortly, which Bugzilla administrators should install as soon as possible.
See also:
- 3.0.3, 3.1.3, 2.22.3, and 2.20.5 Security Advisory, security advisory from the Bugzilla development team
- Download the updated Bugzilla packages.
(mba)