Kod programa Bugzilla, distribuiranog s operacijskim sustavima Fedora 13 i 14, otklonjena je nova ranjivost. Riječ je o aplikaciji za praćenje pogrešaka u programskom kodu koja se oslanja na MySQL ili PostgreSQL bazu podataka. Propust je posljedica nepravilnosti u radu modula "search.pm". Uspješnim iskorištavanjem propusta udaljeni napadači mogu doći u posjed osjetljivih informacija putem zlonamjerno oblikovanih URL adresa. Budući da je dostupna odgovarajuća nadogradnja, svi se korisnici ranjivog paketa potiču na njenu primjenu.

--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-0755
2011-01-25 20:38:09
--------------------------------------------------------------------------------

Name        : bugzilla
Product     : Fedora 13
Version     : 3.4.10
Release     : 1.fc13
URL         : http://www.bugzilla.org/
Summary     : Bug tracking system
Description :
Bugzilla is a popular bug tracking system used by multiple open source projects
It requires a database engine installed - either MySQL, PostgreSQL or Oracle.
Without one of these database engines (local or remote), Bugzilla will not work
- see the Release Notes for details.

--------------------------------------------------------------------------------
Update Information:

Some serious security issues were discovered in Bugzilla and have been fixed in
3.4.10 and 3.6.4.

See http://www.bugzilla.org/security/3.2.9/ for dÊtails.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jan 25 2011 Emmanuel Seyman <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 3.4.10-1
- Update to 3.4.10
* Wed Nov  3 2010 Emmanuel Seyman <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 3.4.9-1
- Update to 3.4.9
* Thu Aug 19 2010 Emmanuel Seyman <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 3.4.8-2
- Bump to correct changelog version
* Wed Aug 18 2010 Emmanuel Seyman <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 3.4.8-1
- Update to 3.4.8 (#623426, #615331)
- Only run checksetup if /etc/bugzilla/localconfig does not exist (#610210)
- Add bugzilla-contrib to Requires (#610198)
* Wed Jun 30 2010 Emmanuel Seyman <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 3.4.7-2
- Remove mod_perl from the requirements (#600924)
* Fri Jun 25 2010 Emmanuel Seyman <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 3.4.7-1
- Update to 3.4.7 (CVE-2010-1204)
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update bugzilla' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce

--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-0741
2011-01-25 20:37:41
--------------------------------------------------------------------------------

Name        : bugzilla
Product     : Fedora 14
Version     : 3.6.4
Release     : 1.fc14
URL         : http://www.bugzilla.org/
Summary     : Bug tracking system
Description :
Bugzilla is a popular bug tracking system used by multiple open source projects
It requires a database engine installed - either MySQL, PostgreSQL or Oracle.
Without one of these database engines (local or remote), Bugzilla will not work
- see the Release Notes for details.

--------------------------------------------------------------------------------
Update Information:

Some serious security issues were discovered in Bugzilla and have been fixed in
3.4.10 and 3.6.4.

See http://www.bugzilla.org/security/3.2.9/ for dÊtails.
--------------------------------------------------------------------------------
ChangeLog:

* Tue Jan 25 2011 Emmanuel Seyman <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 3.6.4-1
- Update to 3.6.4
* Wed Nov  3 2010 Emmanuel Seyman <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 3.6.3-1
- Update to 3.6.3 (#649406)
- Fix webdot alias in /etc/httpd/conf.d/bugzilla (#630255)
- Do not apply graphs patch (upstreamed)
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update bugzilla' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce

Idi na vrh