FreshPorts -- The Place For Ports If you buy from Amazon USA, please support us by using this link.
Follow us
Blog
Twitter

I am looking for an LTO tape library. Do you have one to spare?
Commit found by message id
Thu, 17 Oct 2013
[ 19:35:22 ohauer ] Original commit   Sanity Test Failure  Revision:330666
bugzilla devel  Deleted files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla german  Deleted files touched by this commit  An older version of this port was marked as vulnerable. German localization for Bugzilla
bugzilla japanese  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Japanese localization for Bugzilla
bugzilla russian  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Russian localization for Bugzilla
bugzilla40 devel  Deleted Forbidden Expired Ignore files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla40 german  Deleted files touched by this commit German localization for Bugzilla
bugzilla40 japanese  Deleted files touched by this commit Japanese localization for Bugzilla
bugzilla40 russian  Deleted files touched by this commit Russian localization for Bugzilla
bugzilla42 devel  Deleted Forbidden Expired Ignore files touched by this commit  This port version is marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla42 german  Deleted files touched by this commit  An older version of this port was marked as vulnerable. German localization for Bugzilla
bugzilla42 japanese  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Japanese localization for Bugzilla
bugzilla42 russian  Deleted files touched by this commit  An older version of this port was marked as vulnerable. Russian localization for Bugzilla
bugzilla44 devel files touched by this commit  An older version of this port was marked as vulnerable. Bug-tracking system developed by Mozilla Project
bugzilla44 german files touched by this commit German localization for Bugzilla
bugzilla44 japanese files touched by this commit Japanese localization for Bugzilla
vuxml security files touched by this commit Vulnerability and eXposure Markup Language DTD
head/MOVED
head/devel/Makefile
head/german/Makefile
head/japanese/Makefile
head/russian/Makefile
- update to latest release [1]
- use PKGNAMESUFFIX instead LATEST_LINK
- whitespace cleanup
- svn mv */bugzilla to */bugzilla40
- add vuxml entry

4.4.1, 4.2.7, and 4.0.11 Security Advisory
Wednesday Oct 16th, 2013

Summary
=======

Bugzilla is a Web-based bug-tracking system used by a large number of
software projects. The following security issues have been discovered
in Bugzilla:

* A CSRF vulnerability in process_bug.cgi affecting Bugzilla 4.4 only
  can lead to a bug being edited without the user consent.

* A CSRF vulnerability in attachment.cgi can lead to an attachment
  being edited without the user consent.

* Several unfiltered parameters when editing flagtypes can lead to XSS.

* Due to an incomplete fix for CVE-2012-4189, some incorrectly filtered
  field values in tabular reports can lead to XSS.

All affected installations are encouraged to upgrade as soon as
possible.

[1]  even bugzilla40 gets upstream fixes an upgrade to bugzilla42/44 is
recommend

Security:	vid e135f0c9-375f-11e3-80b7-20cf30e32f6d
		CVE-2013-1733
		CVE-2013-1734
		CVE-2013-1742
		CVE-2013-1743

Number of ports [& non-ports] in this commit: 21

Showing files for just one port: russian/bugzilla

show all files

hide all files


4 files found
ActionRevisionLinksFile
remove 330666 View revision /ports/head/russian/bugzilla
import 330666 View revision /ports/head/russian/bugzilla40
modify 330666 View diff View revision /ports/head/russian/bugzilla40/Makefile
modify 330666 View diff View revision /ports/head/russian/bugzilla42/Makefile
Login
User Login
Create account

Servers and bandwidth provided by
New York Internet, SuperNews, and RootBSD

This site
What is FreshPorts?
About the authors
FAQ
How big is it?
The latest upgrade!
Privacy
Forums
Blog
Contact

Search
Enter Keywords:
 
more...

Latest Vulnerabilities
mcollectiveJul 21
qt4-imageformats*Jul 21
qt5-gui*Jul 21
phpmyadmin*Jul 20
apache24Jul 19
chromiumJul 16
chromiumJul 16
kdelibs4Jul 16
postfixadminJul 13
dbusJul 03
mencoderJun 28
mplayerJun 28
lzo2Jun 26
phpmyadmin*Jun 24
gnupgJun 23

7 vulnerabilities affecting 9 ports have been reported in the past 14 days

* - modified, not new

All vulnerabilities


Ports
Home
Categories
Deleted ports
Sanity Test Failures
Newsfeeds


Statistics
Graphs
NEW Graphs (Javascript)
Traffic

Calculated hourly:
Port count 24467
Broken 194
Deprecated 713
Ignore 528
Forbidden 16
Restricted 263
No CDROM 102
Vulnerable 22
Expired 0
Set to expire 700
Interactive 13
new 24 hours 2
new 48 hours3
new 7 days21
new fortnight52
new month107


Servers and bandwidth provided by
New York Internet, SuperNews, and RootBSD
Valid HTML, CSS, and RSS.
Copyright © 2000-2014 Dan Langille. All rights reserved.