FreshPorts -- The Place For Ports If you buy from Amazon USA, please support us by using this link.
Follow us
Blog
Twitter

I am looking for an LTO tape library. Do you have one to spare?
Commit found by message id
Thu, 17 Oct 2013
[ 19:35:22 ohauer ] Original commit   Sanity Test Failure  Revision:330666
bugzilla devel  Deleted files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla german  Deleted files touched by this commit  An older version of this port was marked as vulnerable. German localization for Bugzilla
bugzilla japanese  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Japanese localization for Bugzilla
bugzilla russian  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Russian localization for Bugzilla
bugzilla40 devel  Deleted Forbidden Expired Ignore files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla40 german  Deleted files touched by this commit German localization for Bugzilla
bugzilla40 japanese  Deleted files touched by this commit Japanese localization for Bugzilla
bugzilla40 russian  Deleted files touched by this commit Russian localization for Bugzilla
bugzilla42 devel  Deleted Forbidden Expired Ignore files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla42 german  Deleted files touched by this commit  An older version of this port was marked as vulnerable. German localization for Bugzilla
bugzilla42 japanese  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Japanese localization for Bugzilla
bugzilla42 russian  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Russian localization for Bugzilla
bugzilla44 devel files touched by this commit  An older version of this port was marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla44 german files touched by this commit German localization for Bugzilla
bugzilla44 japanese files touched by this commit Japanese localization for Bugzilla
vuxml security files touched by this commit Vulnerability and eXposure Markup Language DTD
head/MOVED
head/devel/Makefile
head/german/Makefile
head/japanese/Makefile
head/russian/Makefile
- update to latest release [1]
- use PKGNAMESUFFIX instead LATEST_LINK
- whitespace cleanup
- svn mv */bugzilla to */bugzilla40
- add vuxml entry

4.4.1, 4.2.7, and 4.0.11 Security Advisory
Wednesday Oct 16th, 2013

Summary
=======

Bugzilla is a Web-based bug-tracking system used by a large number of
software projects. The following security issues have been discovered
in Bugzilla:

* A CSRF vulnerability in process_bug.cgi affecting Bugzilla 4.4 only
  can lead to a bug being edited without the user consent.

* A CSRF vulnerability in attachment.cgi can lead to an attachment
  being edited without the user consent.

* Several unfiltered parameters when editing flagtypes can lead to XSS.

* Due to an incomplete fix for CVE-2012-4189, some incorrectly filtered
  field values in tabular reports can lead to XSS.

All affected installations are encouraged to upgrade as soon as
possible.

[1]  even bugzilla40 gets upstream fixes an upgrade to bugzilla42/44 is
recommend

Security:	vid e135f0c9-375f-11e3-80b7-20cf30e32f6d
		CVE-2013-1733
		CVE-2013-1734
		CVE-2013-1742
		CVE-2013-1743

Number of ports [& non-ports] in this commit: 21

Showing files for just one port: german/bugzilla

show all files

hide all files


5 files found
ActionRevisionLinksFile
remove 330666 View revision /ports/head/german/bugzilla
import 330666 View revision /ports/head/german/bugzilla40
modify 330666 View diff View revision /ports/head/german/bugzilla40/Makefile
modify 330666 View diff View revision /ports/head/german/bugzilla42/Makefile
modify 330666 View diff View revision /ports/head/german/bugzilla44/Makefile
Login
User Login
Create account

Servers and bandwidth provided by
New York Internet, SuperNews, and RootBSD

This site
What is FreshPorts?
About the authors
FAQ
How big is it?
The latest upgrade!
Privacy
Forums
Blog
Contact

Search
Enter Keywords:
 
more...

Latest Vulnerabilities
dbusJul 03
mencoderJun 28
mplayerJun 28
lzo2Jun 26
phpmyadmin*Jun 24
gnupgJun 23
gnupg1Jun 23
samba36Jun 23
samba4Jun 23
samba41Jun 23
iodineJun 18
asteriskJun 17
asterisk11Jun 17
dbusJun 14
chromiumJun 10

7 vulnerabilities affecting 10 ports have been reported in the past 14 days

* - modified, not new

All vulnerabilities


Ports
Home
Categories
Deleted ports
Sanity Test Failures
Newsfeeds


Statistics
Graphs
NEW Graphs (Javascript)
Traffic

Calculated hourly:
Port count 24453
Broken 195
Deprecated 588
Ignore 518
Forbidden 2
Restricted 264
No CDROM 102
Vulnerable 26
Expired 4
Set to expire 575
Interactive 14
new 24 hours 5
new 48 hours9
new 7 days37
new fortnight55
new month100


Servers and bandwidth provided by
New York Internet, SuperNews, and RootBSD
Valid HTML, CSS, and RSS.
Copyright © 2000-2014 Dan Langille. All rights reserved.