[SECURITY] Fedora EPEL 5 Update: bugzilla-3.2.10-4.el5

updates at fedoraproject.org updates at fedoraproject.org
Sat Apr 21 20:58:18 UTC 2012


--------------------------------------------------------------------------------
Fedora EPEL Update Notification
FEDORA-EPEL-2012-0352
2012-02-04 20:38:02
--------------------------------------------------------------------------------

Name        : bugzilla
Product     : Fedora EPEL 5
Version     : 3.2.10
Release     : 4.el5
URL         : http://www.bugzilla.org/
Summary     : Bug tracking system
Description :
Bugzilla is a popular bug tracking system used by multiple open source projects
It requires a database engine installed - either MySQL, PostgreSQL or Oracle.
Without one of these database engines (local or remote), Bugzilla will not work
- see the Release Notes for details.

--------------------------------------------------------------------------------
Update Information:

Security fix for CVE-2012-0448 :
* When a user creates a new account, Bugzilla doesn't correctly reject email addresses containing non-ASCII characters, which could be used to impersonate another user account. (CVE-2012-0448)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #786548 - CVE-2012-0440 CVE-2012-0448 bugzila: two flaws fixed in 4.2rc2, 4.0.4, 3.6.8, and 3.4.14
        https://bugzilla.redhat.com/show_bug.cgi?id=786548
--------------------------------------------------------------------------------

This update can be installed with the "yum" update programs.  Use
su -c 'yum update bugzilla' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora EPEL GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------


More information about the epel-package-announce mailing list