—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1
Liebe Kolleginnen und Kollegen,
soeben erreichte uns nachfolgendes Fedora Security Advisory. Wir geben
diese Informationen unveraendert an Sie weiter.
CVE-2009-1213 – Cross-site Request Forgery Schwachstelle in Bugzilla
Durch eine Schwachstelle im attachment.cgi von Bugzilla koennen die
Authentifizierungsdaten von Benutzern fuer Anfragen, welche
Editierfunktionen fuer Anlagen verwenden, von einem entfernten
Angreifer missbraucht werden.
Betroffen sind die folgenden Software Pakete und Plattformen:
Paket bugzilla
Fedora 9
Fedora 10
Vom Hersteller werden ueberarbeitete Pakete zur Verfuegung gestellt.
Hersteller Advisory:
https://www.redhat.com/archives/fedora-package-announce/2009-April/msg00191.html
(c) der deutschen Zusammenfassung bei DFN-CERT Services GmbH; die
Verbreitung, auch auszugsweise, ist nur unter Hinweis auf den Urheber,
DFN-CERT Services GmbH, und nur zu nicht kommerziellen Zwecken
gestattet.
Mit freundlichen Gruessen,
Detlev O. Matthies
– —
Detlev O. Matthies, M.Sc. (Incident Response Team)
DFN-CERT Services GmbH, https://www.dfn-cert.de, Phone +49 40 808077-555
Sitz / Register: Hamburg, AG Hamburg, HRB 88805, Ust-IdNr.: DE 232129737
Sachsenstrasse 5, 20097 Hamburg/Germany, CEO: Dr. Klaus-Peter Kossakowski
Automatische Warnmeldungen https://www.cert.dfn.de/autowarn
– ——————————————————————————–
Fedora Update Notification
FEDORA-2009-3410
2009-04-07 15:17:56
– ——————————————————————————–
Name : bugzilla
Product : Fedora 10
Version : 3.2.3
Release : 1.fc10
URL : http://www.bugzilla.org/
Summary : Bug tracking system
Description :
Bugzilla is a popular bug tracking system used by multiple open source projects
It requires a database engine installed – either MySQL, PostgreSQL or Oracle.
Without one of these database engines (local or remote), Bugzilla will not work
– – see the Release Notes for details.
– ——————————————————————————–
ChangeLog:
* Mon Apr 6 2009 Itamar Reis Peixoto
– – fix CVE-2009-1213
* Thu Mar 5 2009 Itamar Reis Peixoto
– – fix from BZ #474250 Comment #16, from Chris Eveleigh –>
– – add python BR for contrib subpackage
– – fix description
– – change Requires perl-SOAP-Lite to perl(SOAP::Lite) according guidelines
* Sun Mar 1 2009 Itamar Reis Peixoto
– – thanks to Chris Eveleigh
– – for contributing with patches :-)
– – Upgrade to upstream 3.2.2 to fix multiple security vulns
– – Removed old perl_requires exclusions, added new ones for RADIUS, Oracle and sanitycheck.cgi
– – Added Oracle to supported DBs in description (and moved line breaks)
– – Include a patch to fix max_allowed_packet warnin when using with mysql
* Sat Feb 28 2009 Itamar Reis Peixoto
– – Upgrade to 3.0.8, fix #466077 #438080
– – fix macro in changelog rpmlint warning
– – fix files-attr-not-set rpmlint warning for doc and contrib sub-packages
* Mon Feb 23 2009 Fedora Release Engineering
– – Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
* Mon Feb 2 2009 Stepan Kasal
– – do not require perl-Email-Simple, it is (no longer) in use
– – remove several explicit perl-* requires; the automatic dependencies
do handle them
– ——————————————————————————–
References:
[ 1 ] Bug #494398 – CVE-2009-1213 bugzilla: CSRF vulnerability in attachment editing
https://bugzilla.redhat.com/show_bug.cgi?id=494398
– ——————————————————————————–
This update can be installed with the “yum” update program. Use
su -c ‘yum update bugzilla’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
http://fedoraproject.org/keys
– ——————————————————————————–
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.2 (GNU/Linux)
iD8DBQFJ3LbCk0kIxZMiiQ8RAraWAKCnj98FRRyQZIk/Sbcat1MckGBmKgCfddyI
knlLxna4h/Cb57c7XTT9g64=
=VsIS
—–END PGP SIGNATURE—–