Lucene search

K
osvGoogleOSV:DSA-1208-1
HistoryNov 11, 2006 - 12:00 a.m.

bugzilla

2006-11-1100:00:00
Google
osv.dev
10

EPSS

0.006

Percentile

78.5%

Several remote vulnerabilities have been discovered in the Bugzilla
bug tracking system, which may lead to the execution of arbitrary code.
The Common Vulnerabilities and Exposures project identifies the following
problems:

  • CVE-2005-4534
    Javier FernĂĄndez-Sanguino PeĂąa discovered that insecure temporary
    file usage may lead to denial of service through a symlink attack.
  • CVE-2006-5453
    Several cross-site scripting vulnerabilities may lead to injection
    of arbitrary web script code.

For the stable distribution (sarge) these problems have been fixed in
version 2.16.7-7sarge2.

For the upcoming stable distribution (etch) these problems have been
fixed in version 2.22.1-1.

For the unstable distribution (sid) these problems have been fixed in
version 2.22.1-1.

We recommend that you upgrade your bugzilla packages.