~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
Candidate: CVE-2009-0483
PublicDate: 2009-02-09
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0483
Description:
 Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.22 before
 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows
 remote attackers to delete keywords and user preferences via a link or IMG
 tag to (1) editkeywords.cgi or (2) userprefs.cgi.
Ubuntu-Description:
Notes:
Bugs:
Priority: low
Discovered-by:
Assigned-to:

Patches_bugzilla:
upstream_bugzilla: released (3.2.4.0-3)
dapper_bugzilla: ignored (reached end-of-life)
gutsy_bugzilla: needed (reached end-of-life)
hardy_bugzilla: ignored (reached end-of-life)
intrepid_bugzilla: needed (reached end-of-life)
jaunty_bugzilla: ignored (reached end-of-life)
karmic_bugzilla: not-affected (3.2.4.0-3)
lucid_bugzilla: not-affected (3.2.4.0-3)
maverick_bugzilla: not-affected (3.2.4.0-3)
natty_bugzilla: not-affected (3.2.4.0-3)
oneiric_bugzilla: not-affected (3.2.4.0-3)
devel_bugzilla: not-affected (3.2.4.0-3)