Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 114004 - Gentoo Bugzilla 2.18.3 requires security issue update to 2.18.4
Summary: Gentoo Bugzilla 2.18.3 requires security issue update to 2.18.4
Status: RESOLVED DUPLICATE of bug 99714
Alias: None
Product: Gentoo Infrastructure
Classification: Unclassified
Component: Bugzilla (show other bugs)
Hardware: All Linux
: High critical
Assignee: Jeffrey Forman (RETIRED)
URL: http://www.bugzilla.org/releases/2.18.4/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-11-30 02:29 UTC by Gary Kwong [:gkw] [:nth10sd]
Modified: 2011-10-30 23:14 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gary Kwong [:gkw] [:nth10sd] 2005-11-30 02:29:28 UTC
Note: This is for the 2.18.3 Bugzilla version Gentoo is currently using. It has
already been noted for the metabug regarding 2.20 (#99714).

Security issue fixed in 2.18.4:

Vulnerability Details
=====================

Issue 1
-------
Class:       Information Leak
Versions:    2.18rc1 - 2.18.3, 2.19 - 2.20rc2, 2.21
Description: config.cgi gives JavaScript and RDF information about Bugzilla
             to third-party clients, including a list of products in the
             Bugzilla installation. The "requirelogin" parameter requires
             that all people be logged into Bugzilla before seeing any data,
             as a security measure.
             In affected versions, config.cgi is always accessible, and always
             contains information to non-logged-in users, even when 
             "requirelogin" is turned on, possibly exposing product names that
             administrators expected to be confidential.
Reference:   https://bugzilla.mozilla.org/show_bug.cgi?id=308256
Comment 1 Jakub Moc (RETIRED) gentoo-dev 2005-11-30 03:49:26 UTC

*** This bug has been marked as a duplicate of 99714 ***