https://bugzilla.redhat.com/show_bug.cgi?id=1295438
Bug ID: 1295438 Summary: CVE-2015-8509 bugzilla: information leak when parsing the CSV file Product: Security Response Component: vulnerability Keywords: Security Severity: medium Priority: medium Assignee: security-response-team@redhat.com Reporter: mprpic@redhat.com CC: bazanluis20@gmail.com, emmanuel@seyman.fr, itamar@ispbrasil.com.br, perl-devel@lists.fedoraproject.org
Upstream Bugzilla fixed the following issue:
If an external HTML page contains a <script> element with its src attribute pointing to a buglist in CSV format, some web browsers incorrectly try to parse the CSV file as valid JavaScript code. As the buglist is generated based on the privileges of the user logged into Bugzilla, the external page could collect confidential data contained in the CSV file.
This issue was fixed in versions 4.2.16, 4.4.11, and 5.0.2.
Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=1232785
https://bugzilla.redhat.com/show_bug.cgi?id=1295438
Martin Prpic mprpic@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Depends On| |1295439
--- Comment #1 from Martin Prpic mprpic@redhat.com ---
Created bugzilla tracking bugs for this issue:
Affects: fedora-all [bug 1295439]
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=1295439 [Bug 1295439] CVE-2015-8509 bugzilla: information leak when parsing the CSV file [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1295438
Emmanuel Seyman emmanuel@seyman.fr changed:
What |Removed |Added ---------------------------------------------------------------------------- CC| |emmanuel@seyman.fr
--- Comment #2 from Emmanuel Seyman emmanuel@seyman.fr --- The update that fixes this issue was published late 2015 (this is update FEDORA-2015-247b517a18, btw). I'm quite confident that this bug can be closed.
https://bugzilla.redhat.com/show_bug.cgi?id=1295438 Bug 1295438 depends on bug 1295439, which changed state.
Bug 1295439 Summary: CVE-2015-8509 bugzilla: information leak when parsing the CSV file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1295439
What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |CLOSED Resolution|--- |EOL
perl-devel@lists.fedoraproject.org