Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 524316 (CVE-2014-1572, CVE-2014-1573)

Summary: <www-apps/bugzilla-4.4.5: Exploit (CVE-2014-1572)
Product: Gentoo Security Reporter: Robin Johnson <robbat2>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: idl0r
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: All   
Whiteboard: B1 [glsa]
Package list:
Runtime testing required: ---

Description Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2014-10-02 19:50:08 UTC
This is not public yet, but the Gentoo Bugzilla has been partially patched already.

I haven't included the name of it, because that would give away a large of where & what it is; it's nasty however.

Upstream bugs:
https://bugzilla.mozilla.org/show_bug.cgi?id=1075578
https://bugzilla.mozilla.org/show_bug.cgi?id=1074812

Embargo end date is targeted for Monday, Oct 6, 14:00 UTC.
Comment 1 Aaron Bauman (RETIRED) gentoo-dev 2016-07-10 06:20:56 UTC
Both bugs are publicly accessible upstream now.  Opening bug.

Added to existing GLSA.
Comment 2 GLSAMaker/CVETool Bot gentoo-dev 2016-07-20 11:16:08 UTC
This issue was resolved and addressed in
 GLSA 201607-11 at https://security.gentoo.org/glsa/201607-11
by GLSA coordinator Aaron Bauman (b-man).