~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2015-8346

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2015-8346
2
 
PublicDate: 2016-04-12
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8346
5
 
 https://www.redmine.org/projects/redmine/wiki/Changelog_3_0
6
 
 https://www.redmine.org/projects/redmine/wiki/Security_Advisories
7
 
 http://www.openwall.com/lists/oss-security/2015/11/25/1
8
 
Description:
9
 
 app/views/timelog/_form.html.erb in Redmine before 2.6.8, 3.0.x before
10
 
 3.0.6, and 3.1.x before 3.1.2 allows remote attackers to obtain sensitive
11
 
 information about subjects of issues by viewing the time logging form.
12
 
Ubuntu-Description:
13
 
Notes:
14
 
 tyhicks> Fixed in 2.6.8, 3.0.6 and 3.1.2
15
 
Bugs:
16
 
 https://www.redmine.org/issues/21150 (private)
17
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=806376
18
 
Priority: low
19
 
Discovered-by:
20
 
Assigned-to:
21
 
 
22
 
Patches_redmine:
23
 
upstream_redmine: released (3.1.2)
24
 
precise_redmine: ignored (reached end-of-life)
25
 
precise/esm_redmine: DNE (precise was needed)
26
 
trusty_redmine: needed
27
 
vivid_redmine: ignored (reached end-of-life)
28
 
vivid/stable-phone-overlay_redmine: DNE
29
 
vivid/ubuntu-core_redmine: DNE
30
 
wily_redmine: ignored (reached end-of-life)
31
 
xenial_redmine: not-affected (3.2.0-1)
32
 
yakkety_redmine: ignored (reached end-of-life)
33
 
zesty_redmine: ignored (reached end-of-life)
34
 
artful_redmine: not-affected (3.2.0-1)
35
 
bionic_redmine: not-affected (3.2.0-1)
36
 
devel_redmine: not-affected (3.2.0-1)