stable

bugzilla-4.4.12-1.fc23

FEDORA-2016-6cdcddef2c created by eseyman 8 years ago for Fedora 23

The bugzilla devs discovered that a specially crafted bug summary could trigger XSS in dependency graphs (CVE-2016-2803). This release fixes the issue.


A bug in Bugzilla caused it to send improperly formatted email addresses. This update contains the fix to this problem.

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2016-6cdcddef2c

This update has been submitted for testing by eseyman.

8 years ago

This update has obsoleted bugzilla-4.4.11-2.fc23, and has inherited its bugs and notes.

8 years ago

This update has been pushed to testing.

8 years ago

This update has reached 7 days in testing and can be pushed to stable now if the maintainer wishes

8 years ago

This update has been submitted for stable by eseyman.

8 years ago

This update has been pushed to stable.

8 years ago

Please login to add feedback.

Metadata
Type
security
Karma
0
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
disabled
Dates
submitted
8 years ago
in testing
8 years ago
in stable
8 years ago
BZ#1305061 perl-Encode-2.80 breaks sending email by bugzilla
0
0
BZ#1336671 CVE-2016-2803 bugzilla: Cross-site-scripting in dependency graphs
0
0
BZ#1336672 CVE-2016-2803 bugzilla: Cross-site-scripting in dependency graphs [fedora-all]
0
0

Automated Test Results