Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 165173 - www-apps/bugzilla XSS CVE-2007-0792
Summary: www-apps/bugzilla XSS CVE-2007-0792
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://www.securityfocus.com/archive/...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2007-02-03 21:18 UTC by Executioner
Modified: 2007-02-09 14:57 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Executioner 2007-02-03 21:18:16 UTC
A possible cross-site scripting (XSS) vulnerability in Atom feeds
produced by Bugzilla.


Reproducible: Didn't try




http://www.securityfocus.com/archive/1/459025
Comment 1 Executioner 2007-02-03 21:20:49 UTC
http://www.securityfocus.com/bid/22380/info
Comment 2 Renat Lumpau (RETIRED) gentoo-dev 2007-02-03 23:31:30 UTC
in CVS
Comment 3 Executioner 2007-02-07 06:14:25 UTC
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-0792
Comment 4 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-02-09 14:57:14 UTC
Stable ebuilds not affected. Closing.