FreshPorts -- The Place For Ports If you buy from Amazon USA, please support us by using this link.
Follow us
Blog
Twitter

I am looking for an LTO tape library. Do you have one to spare?
Commit found by message id
Thu, 17 Oct 2013
[ 19:35:22 ohauer ] Original commit   Sanity Test Failure  Revision:330666
bugzilla devel  Deleted files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla german  Deleted files touched by this commit  An older version of this port was marked as vulnerable. German localization for Bugzilla
bugzilla japanese  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Japanese localization for Bugzilla
bugzilla russian  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Russian localization for Bugzilla
bugzilla40 devel  Deleted Forbidden Expired Ignore files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla40 german  Deleted files touched by this commit German localization for Bugzilla
bugzilla40 japanese  Deleted files touched by this commit Japanese localization for Bugzilla
bugzilla40 russian  Deleted files touched by this commit Russian localization for Bugzilla
bugzilla42 devel  Deleted Forbidden Expired Ignore files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla42 german  Deleted files touched by this commit  An older version of this port was marked as vulnerable. German localization for Bugzilla
bugzilla42 japanese  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Japanese localization for Bugzilla
bugzilla42 russian  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Russian localization for Bugzilla
bugzilla44 devel files touched by this commit  An older version of this port was marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla44 german files touched by this commit German localization for Bugzilla
bugzilla44 japanese files touched by this commit Japanese localization for Bugzilla
vuxml security files touched by this commit Vulnerability and eXposure Markup Language DTD
head/MOVED
head/devel/Makefile
head/german/Makefile
head/japanese/Makefile
head/russian/Makefile
- update to latest release [1]
- use PKGNAMESUFFIX instead LATEST_LINK
- whitespace cleanup
- svn mv */bugzilla to */bugzilla40
- add vuxml entry

4.4.1, 4.2.7, and 4.0.11 Security Advisory
Wednesday Oct 16th, 2013

Summary
=======

Bugzilla is a Web-based bug-tracking system used by a large number of
software projects. The following security issues have been discovered
in Bugzilla:

* A CSRF vulnerability in process_bug.cgi affecting Bugzilla 4.4 only
  can lead to a bug being edited without the user consent.

* A CSRF vulnerability in attachment.cgi can lead to an attachment
  being edited without the user consent.

* Several unfiltered parameters when editing flagtypes can lead to XSS.

* Due to an incomplete fix for CVE-2012-4189, some incorrectly filtered
  field values in tabular reports can lead to XSS.

All affected installations are encouraged to upgrade as soon as
possible.

[1]  even bugzilla40 gets upstream fixes an upgrade to bugzilla42/44 is
recommend

Security:	vid e135f0c9-375f-11e3-80b7-20cf30e32f6d
		CVE-2013-1733
		CVE-2013-1734
		CVE-2013-1742
		CVE-2013-1743

Number of ports [& non-ports] in this commit: 21

Showing files for just one port: german/bugzilla44

show all files

hide all files


1 file found
ActionRevisionLinksFile
modify 330666 View diff View revision /ports/head/german/bugzilla44/Makefile
Login
User Login
Create account

Servers and bandwidth provided by
New York Internet, SuperNews, and RootBSD

This site
What is FreshPorts?
About the authors
FAQ
How big is it?
The latest upgrade!
Privacy
Forums
Blog
Contact

Search
Enter Keywords:
 
more...

Latest Vulnerabilities
asterisk11Sep 18
squidSep 18
squid33Sep 18
dbusSep 17
nginxSep 16
nginx-develSep 16
phpmyadminSep 13
ossec-hids-clientSep 11
ossec-hids-localSep 11
ossec-hids-serverSep 11
chromiumSep 09
trafficserverSep 05
apache22*Sep 03
apache22-event-mpm*Sep 03
apache22-itk-mpm*Sep 03

8 vulnerabilities affecting 19 ports have been reported in the past 14 days

* - modified, not new

All vulnerabilities


Ports
Home
Categories
Deleted ports
Sanity Test Failures
Newsfeeds


Statistics
Graphs
NEW Graphs (Javascript)
Traffic

Calculated hourly:
Port count 24062
Broken 118
Deprecated 53
Ignore 370
Forbidden 4
Restricted 203
No CDROM 94
Vulnerable 21
Expired 5
Set to expire 48
Interactive 0
new 24 hours 6
new 48 hours8
new 7 days37
new fortnight68
new month233


Servers and bandwidth provided by
New York Internet, SuperNews, and RootBSD
Valid HTML, CSS, and RSS.
Copyright © 2000-2014 Dan Langille. All rights reserved.