Closed
Bug 529481
Opened 15 years ago
Closed 15 years ago
Security Advisory for Bugzilla 3.5.2 and 3.4.4
Categories
(Bugzilla :: Documentation, defect)
Tracking
()
RESOLVED
FIXED
People
(Reporter: mkanat, Assigned: mkanat)
References
Details
Attachments
(1 file, 2 obsolete files)
(deleted),
patch
|
mkanat
:
review+
|
Details | Diff | Splinter Review |
No description provided.
Assignee | ||
Updated•15 years ago
|
Blocks: bz-release-344
Assignee | ||
Comment 1•15 years ago
|
||
Updated•15 years ago
|
Attachment #413188 -
Attachment is patch: false
Attachment #413188 -
Flags: review?(LpSolit) → review-
Comment 2•15 years ago
|
||
Comment on attachment 413188 [details]
v1
>* Aliases of hidden bugs would show up in the "Depends On" and "Blocks"
> list of other bugs, even if you didn't have the power to see the
> hidden bug.
"...to see the hidden bugs" (plural) as you said "Aliases of hidden bugs" (plural)?
>Versions: 3.3.2 to 3.4.3, 3.5 to 3.5.2
s/3.5.2/3.5.1/.
>Fixed In: 3.3.4, 3.5.2
s/3.3.4/3.4.4/.
>The fixes for these issues are included in the 3.4.4 and 3.5.2
There is only one issue.
>releases. Upgrading to a release with the relevant fixes will protect
Only one fix.
>your installation from possible exploits of these issues.
And here.
>individual security vulnerabilities, there are patches available for
>the individual issues in the Reference URLs of each advisory.
And here.
>Jesse Ruderman
>Dave Miller
>Max Kanat-Alexander
>Frédéric Buclin
We usually list users as follow: patch author (justdave), reviewers (you and me), reporter (Jesse). And my name should be written in UTF8.
Assignee | ||
Comment 3•15 years ago
|
||
Okay, this addresses all those issues (except that I believe that your name is in fact written in UTF-8 already, it's just that UTF-8 bug with attachments you're experiencing).
Attachment #413188 -
Attachment is obsolete: true
Attachment #413194 -
Flags: review?(LpSolit)
Comment 4•15 years ago
|
||
Comment on attachment 413194 [details]
v2
>Bugzilla is a Web-based bug-tracking system, used by a large number of
>software projects.
Drop the comma, please.
>* Aliases of hidden bugs would show up in the "Depends On" and "Blocks"
> list of other bugs, even if you didn't have the power to see the
> hidden bugs.
s/the power/permission/
Comment 5•15 years ago
|
||
Comment on attachment 413194 [details]
v2
great! r=LpSolit
Attachment #413194 -
Flags: review?(LpSolit) → review+
Assignee | ||
Comment 6•15 years ago
|
||
Thanks! This is the version with reed's two comments fixed.
Attachment #413194 -
Attachment is obsolete: true
Attachment #413195 -
Flags: review+
Assignee | ||
Comment 7•15 years ago
|
||
Sent.
Group: bugzilla-security
Status: ASSIGNED → RESOLVED
Closed: 15 years ago
Resolution: --- → FIXED
You need to log in
before you can comment on or make changes to this bug.
Description
•