FreshPorts -- The Place For Ports If you buy from Amazon USA, please support us by using this link.
Follow us
Blog
Twitter

I am looking for an LTO tape library. Do you have one to spare?
Commit found by message id
Thu, 17 Oct 2013
[ 19:35:22 ohauer ] Original commit   Sanity Test Failure  Revision:330666
bugzilla devel  Deleted files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla german  Deleted files touched by this commit  An older version of this port was marked as vulnerable. German localization for Bugzilla
bugzilla japanese  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Japanese localization for Bugzilla
bugzilla russian  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Russian localization for Bugzilla
bugzilla40 devel  Deleted Forbidden Expired Ignore files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla40 german  Deleted files touched by this commit German localization for Bugzilla
bugzilla40 japanese  Deleted files touched by this commit Japanese localization for Bugzilla
bugzilla40 russian  Deleted files touched by this commit Russian localization for Bugzilla
bugzilla42 devel  Deleted Forbidden Expired Ignore files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla42 german  Deleted files touched by this commit  An older version of this port was marked as vulnerable. German localization for Bugzilla
bugzilla42 japanese  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Japanese localization for Bugzilla
bugzilla42 russian  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Russian localization for Bugzilla
bugzilla44 devel files touched by this commit  An older version of this port was marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla44 german files touched by this commit German localization for Bugzilla
bugzilla44 japanese files touched by this commit Japanese localization for Bugzilla
vuxml security files touched by this commit Vulnerability and eXposure Markup Language DTD
head/MOVED
head/devel/Makefile
head/german/Makefile
head/japanese/Makefile
head/russian/Makefile
- update to latest release [1]
- use PKGNAMESUFFIX instead LATEST_LINK
- whitespace cleanup
- svn mv */bugzilla to */bugzilla40
- add vuxml entry

4.4.1, 4.2.7, and 4.0.11 Security Advisory
Wednesday Oct 16th, 2013

Summary
=======

Bugzilla is a Web-based bug-tracking system used by a large number of
software projects. The following security issues have been discovered
in Bugzilla:

* A CSRF vulnerability in process_bug.cgi affecting Bugzilla 4.4 only
  can lead to a bug being edited without the user consent.

* A CSRF vulnerability in attachment.cgi can lead to an attachment
  being edited without the user consent.

* Several unfiltered parameters when editing flagtypes can lead to XSS.

* Due to an incomplete fix for CVE-2012-4189, some incorrectly filtered
  field values in tabular reports can lead to XSS.

All affected installations are encouraged to upgrade as soon as
possible.

[1]  even bugzilla40 gets upstream fixes an upgrade to bugzilla42/44 is
recommend

Security:	vid e135f0c9-375f-11e3-80b7-20cf30e32f6d
		CVE-2013-1733
		CVE-2013-1734
		CVE-2013-1742
		CVE-2013-1743

Number of ports [& non-ports] in this commit: 21

Showing files for just one port: japanese/bugzilla44

show all files

hide all files


1 file found
ActionRevisionLinksFile
modify 330666 View diff View revision /ports/head/japanese/bugzilla44/Makefile
Login
User Login
Create account

Servers and bandwidth provided by
New York Internet, SuperNews, and RootBSD

This site
What is FreshPorts?
About the authors
FAQ
How big is it?
The latest upgrade!
Privacy
Forums
Blog
Contact

Search
Enter Keywords:
 
more...

Latest Vulnerabilities
chromiumAug 26
fileAug 21
py-djangoAug 21
py-django-develAug 21
py-django14Aug 21
py-django15Aug 21
php53Aug 18
phpmyadminAug 17
chromiumAug 13
serfAug 11
subversionAug 11
subversion17Aug 11
nginxAug 09
nginx-develAug 09
mingw32-opensslAug 06

6 vulnerabilities affecting 9 ports have been reported in the past 14 days

* - modified, not new

All vulnerabilities


Ports
Home
Categories
Deleted ports
Sanity Test Failures
Newsfeeds


Statistics
Graphs
NEW Graphs (Javascript)
Traffic

Calculated hourly:
Port count 24510
Broken 217
Deprecated 730
Ignore 561
Forbidden 36
Restricted 261
No CDROM 101
Vulnerable 23
Expired 0
Set to expire 720
Interactive 0
new 24 hours 6
new 48 hours8
new 7 days55
new fortnight95
new month255


Servers and bandwidth provided by
New York Internet, SuperNews, and RootBSD
Valid HTML, CSS, and RSS.
Copyright © 2000-2014 Dan Langille. All rights reserved.