https://bugzilla.redhat.com/show_bug.cgi?id=1336671
Bug ID: 1336671
Summary: CVE-2016-2803 bugzilla: Cross-site-scripting in
dependency graphs
Product: Security Response
Component: vulnerability
Keywords: Security
Severity: medium
Priority: medium
Assignee: security-response-team(a)redhat.com
Reporter: anemec(a)redhat.com
CC: bazanluis20(a)gmail.com, emmanuel(a)seyman.fr,
itamar(a)ispbrasil.com.br,
perl-devel(a)lists.fedoraproject.org,
xavier(a)bachelot.org
A vulnerability was found in the bugzilla application. Due to an incorrect
parsing of the image map generated by the dot script, a specially crafted bug
summary could trigger XSS in dependency graphs.
External references:
https://bugzilla.mozilla.org/show_bug.cgi?id=1253263
References:
http://seclists.org/bugtraq/2016/May/72
Upstream fix:
https://git.mozilla.org/?p=bugzilla/bugzilla.git;a=commitdiff;h=dd61903
--
You are receiving this mail because:
You are on the CC list for the bug.