| Commit History - (may be incomplete: see CVSWeb link above for full details) |
| Date | By | Description |
21 Apr 2012 17:37:42
4.0.5_1
|
ohauer  |
- security update to bugzilla 3.0.9 and 4.0.6
- update russian/bugzilla3-ru template
- patch german templates so revision match and no warning is displayed
- add vuxml entry
Approved by: skv (implicit)
Security: https://bugzilla.mozilla.org/show_bug.cgi?id=728639
https://bugzilla.mozilla.org/show_bug.cgi?id=745397
CVE-2012-0465
CVE-2012-0466 |
10 Apr 2012 05:15:48
4.0.5
|
ohauer  |
- update to 4.0.5
Vulnerability Details
=====================
Class: Cross-Site Request Forgery
Versions: 4.0.2 to 4.0.4, 4.1.1 to 4.2rc2
Fixed In: 4.0.5, 4.2
Description: Due to a lack of validation of the enctype form
attribute when making POST requests to xmlrpc.cgi,
a possible CSRF vulnerability was discovered. If a user
visits an HTML page with some malicious HTML code in it,
an attacker could make changes to a remote Bugzilla installation
on behalf of the victim's account by using the XML-RPC API
on a site running mod_perl. Sites running under mod_cgi
are not affected. Also the user would have had to be
already logged in to the target site for the vulnerability
to work.
References: https://bugzilla.mozilla.org/show_bug.cgi?id=725663
CVE Number: CVE-2012-0453
Approved by: skv (implicit) |
13 Feb 2012 21:14:34
4.0.4
|
ohauer  |
- update german bugzilla templates |
05 Jan 2012 17:30:45
4.0.3
|
ohauer  |
- update german bugzilla translations |
14 Aug 2011 18:56:47
4.0.2
|
ohauer  |
- update german bugzilla language templates |
18 Jul 2011 21:56:02
4.0.1
|
ohauer  |
- create missing (empty) directory (bugzilla) so checksetup does not fail
- use DIST_SUBDIR for bugzilla and all translations
- sort pkg-plist (genplist)
OK from bugzilla maintainers per PM.
PR: ports/158766
Submitted by: ohauer |
11 Jun 2011 19:04:02
4.0.1
|
ohauer  |
- add German localization for Bugzilla bug tracking system |