~ubuntu-branches/ubuntu/gutsy/bugzilla/gutsy-security

  • Committer: Bazaar Package Importer
  • Author(s): Stefan Lesicnik
  • Date: 2008-10-11 21:56:21 UTC
  • Revision ID: james.westby@ubuntu.com-20081011215621-nvj6e1d7sliyiix0
Tags: 2.22.1-2.2ubuntu1.7.10.1
* SECURITY UPDATE: Directory traversal vulnerability in importxml.pl in
  Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path 
  is enabled, allows remote attackers to read arbitrary files via an
  XML file with a .. (dot dot) in the data element.(LP: #281915)
  - debian/patches/CVE-2008-4437.dpatch: upstream patch with regex
    to remove any leading path data from the filename.
  - CVE-2008-4437
Filename Latest Rev Last Changed Committer Comment Size
..
Bugzilla 1.1.2 18 years ago Bazaar Package Importer Import upstream version 2.18.4 Diff
contrib 1 20 years ago Bazaar Package Importer Import upstream version 2.16.5 Diff
debian 2 20 years ago Bazaar Package Importer Duplicate table creation is now also fixed in bugz Diff
docs 1 20 years ago Bazaar Package Importer Import upstream version 2.16.5 Diff
images 1.1.3 18 years ago Bazaar Package Importer Import upstream version 2.20 Diff
js 1.1.2 18 years ago Bazaar Package Importer Import upstream version 2.18.4 Diff
skins 1.1.2 18 years ago Bazaar Package Importer Import upstream version 2.18.4 Diff
t 1 20 years ago Bazaar Package Importer Import upstream version 2.16.5 Diff
template 1 20 years ago Bazaar Package Importer Import upstream version 2.16.5 Diff
File attachment.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 45.5 KB Diff Download File
File buglist.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 46.1 KB Diff Download File
bugzilla.dtd 1.1.4 18 years ago Bazaar Package Importer Import upstream version 2.22 2.6 KB Diff Download File
Bugzilla.pm 1.1.5 17 years ago Bazaar Package Importer Import upstream version 2.22.1 12.9 KB Diff Download File
File chart.cgi 1.1.4 18 years ago Bazaar Package Importer Import upstream version 2.22 9.7 KB Diff Download File
File checksetup.pl 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 188 KB Diff Download File
File colchange.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 4.5 KB Diff Download File
File collectstats.pl 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 17.2 KB Diff Download File
File config.cgi 1.1.4 18 years ago Bazaar Package Importer Import upstream version 2.22 3.4 KB Diff Download File
File createaccount.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 3.1 KB Diff Download File
File describecomponents.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 3.5 KB Diff Download File
File describekeywords.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 1.7 KB Diff Download File
File duplicates.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 9.2 KB Diff Download File
duplicates.xul 1.1.3 18 years ago Bazaar Package Importer Import upstream version 2.20 6.5 KB Diff Download File
File editclassifications.cgi 1.1.5 17 years ago Bazaar Package Importer Import upstream version 2.22.1 7.9 KB Diff Download File
File editcomponents.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 12.2 KB Diff Download File
File editflagtypes.cgi 1.1.5 17 years ago Bazaar Package Importer Import upstream version 2.22.1 24 KB Diff Download File
File editgroups.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 26 KB Diff Download File
File editkeywords.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 8 KB Diff Download File
File editmilestones.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 10.3 KB Diff Download File
File editparams.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 4.5 KB Diff Download File
File editproducts.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 38.1 KB Diff Download File
File editsettings.cgi 1.1.5 17 years ago Bazaar Package Importer Import upstream version 2.22.1 2.9 KB Diff Download File
File editusers.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 33 KB Diff Download File
File editvalues.cgi 1.1.5 17 years ago Bazaar Package Importer Import upstream version 2.22.1 12.5 KB Diff Download File
File editversions.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 8.2 KB Diff Download File
File editwhines.cgi 1.1.5 17 years ago Bazaar Package Importer Import upstream version 2.22.1 18.6 KB Diff Download File
File enter_bug.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 21.8 KB Diff Download File
globals.pl 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 27.9 KB Diff Download File
File importxml.pl 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 46.6 KB Diff Download File
File index.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 1.9 KB Diff Download File
File long_list.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 1.2 KB Diff Download File
Makefile 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 4.6 KB Diff Download File
File page.cgi 1.1.4 18 years ago Bazaar Package Importer Import upstream version 2.22 1.9 KB Diff Download File
File post_bug.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 16.5 KB Diff Download File
File process_bug.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 81 KB Diff Download File
productmenu.js 1.1.4 18 years ago Bazaar Package Importer Import upstream version 2.22 9 KB Diff Download File
File query.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 15.2 KB Diff Download File
QUICKSTART 1.1.4 18 years ago Bazaar Package Importer Import upstream version 2.22 3.5 KB Diff Download File
File quips.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 4.3 KB Diff Download File
README 1.1.2 18 years ago Bazaar Package Importer Import upstream version 2.18.4 892 bytes Diff Download File
File relogin.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 7.4 KB Diff Download File
File report.cgi 1.1.4 18 years ago Bazaar Package Importer Import upstream version 2.22 12.5 KB Diff Download File
File reports.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 9.5 KB Diff Download File
File request.cgi 1.1.5 17 years ago Bazaar Package Importer Import upstream version 2.22.1 13 KB Diff Download File
robots.txt 1 20 years ago Bazaar Package Importer Import upstream version 2.16.5 44 bytes Diff Download File
File runtests.pl 1.1.2 18 years ago Bazaar Package Importer Import upstream version 2.18.4 1.1 KB Diff Download File
File sanitycheck.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 31.1 KB Diff Download File
File show_activity.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 1.9 KB Diff Download File
File show_bug.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 3.7 KB Diff Download File
File showattachment.cgi 3.1.1 18 years ago Bazaar Package Importer * New upstream minor release + Fixed a security 1.1 KB Diff Download File
File showdependencygraph.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 9.1 KB Diff Download File
File showdependencytree.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 6.7 KB Diff Download File
File sidebar.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 1.7 KB Diff Download File
File summarize_time.cgi 1.1.4 18 years ago Bazaar Package Importer Import upstream version 2.22 17.1 KB Diff Download File
File testagent.cgi 1.1.2 18 years ago Bazaar Package Importer Import upstream version 2.18.4 836 bytes Diff Download File
File testserver.pl 1.1.5 17 years ago Bazaar Package Importer Import upstream version 2.22.1 8.3 KB Diff Download File
File token.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 11.8 KB Diff Download File
UPGRADING 1 20 years ago Bazaar Package Importer Import upstream version 2.16.5 188 bytes Diff Download File
UPGRADING-pre-2.8 1.1.2 18 years ago Bazaar Package Importer Import upstream version 2.18.4 17.9 KB Diff Download File
File userprefs.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 16.5 KB Diff Download File
File votes.cgi 3.1.4 17 years ago Bazaar Package Importer * New upstream release (2.22.1) fixes several secu 13.5 KB Diff Download File
File whine.pl 1.1.4 18 years ago Bazaar Package Importer Import upstream version 2.22 24.4 KB Diff Download File
File whineatnews.pl 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 2.5 KB Diff Download File
File xml.cgi 3.1.3 18 years ago Bazaar Package Importer * New upstream release (2.22). (closes: #365304) 1.2 KB Diff Download File