Security advisory for Bugzilla 4.5.6, 4.4.6, 4.2.11, and 4.0.15 #2-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Summary
=======
Bugzilla is a Web-based bug-tracking system used by a large number of
software projects. The following security issues have been discovered
in Bugzilla:
* The 'realname' parameter is not correctly filtered on user account
creation, which could lead to user data override.
* Several places were found in the Bugzilla code where cross-site
scripting attacks could be used to access sensitive information.
* Private comments can be shown to flagmail recipients who aren't in
the insider group
* Specially...
Security advisory for Bugzilla 4.5.6, 4.4.6, 4.2.11, and 4.0.15Summary
=======
Bugzilla is a Web-based bug-tracking system used by a large number of
software projects. The following security issues have been discovered
in Bugzilla:
* The 'realname' parameter is not correctly filtered on user account
creation, which could lead to user data override.
* Several places were found in the Bugzilla code where cross-site
scripting attacks could be used to access sensitive information.
* Private comments can be shown to flagmail recipients who aren't in
the insider group
* Specially formatted values in a CSV search results export c...
[ANN] Release of Bugzilla 4.5.4, 4.4.4, 4.2.9, and 4.0.13 Today we are releasing 4.4.4, 4.2.9, 4.0.13, and the unstable
development snapshot 4.5.4. All releases fix a regression discovered
since the last release.
Bugzilla 4.4.4 is our latest stable release. Bugzilla 4.4.4,
4.2.9 and 4.0.13 are bug fix updates for the 4.4, 4.2, and the
4.0 branches, respectively.
Note that 4.5.4 is an unstable development release and should not
be used in production environments. We are not yet feature-frozen at
this time so the features you see in 4.5.4 might not accurately
represent the behavior that 5.0 will have.
Note that when Bugzilla...
[ANN] Release of Bugzilla 4.5.1, 4.4.1, 4.2.7, and 4.0.11 Today we are releasing 4.4.1, 4.2.7, 4.0.11, and the unstable
development snapshot 4.5.1.
Initially, we released new tarballs and diffs for these releases
to the download site but found a new bug shortly after. New tarballs
and diffs have been uploaded to the site which we recommend everyone
update to if you downloaded the first version. To make sure you
have the fixed version, md5sum values are provided further down in
the announcement.
All of today's releases contain security fixes. We recommend
all Bugzilla administrators to read the Security Advisory linked below.
...
[ANN] Release of Bugzilla 4.5.5, 4.4.5, 4.2.10, and 4.0.14 Today we are releasing 4.4.5, 4.2.10, 4.0.14, and the unstable
development snapshot 4.5.5. All releases fix a security issue found
since the last release.
Bugzilla 4.4.5 is our latest stable release. Bugzilla 4.4.5,
4.2.10 and 4.0.14 are security updates for the 4.4, 4.2, and the
4.0 branches, respectively.
Note that 4.5.5 is an unstable development release and should not
be used in production environments. We are not yet feature-frozen at
this time so the features you see in 4.5.5 might not accurately
represent the behavior that 5.0 will have.
Note that when Bugzilla 5...
[ANN] Release of Bugzilla 4.1.2, 4.0.1, 3.6.5, and 3.4.11 Today we are releasing 4.0.1, 3.6.5, 3.4.11, and the unstable
development snapshot 4.1.2.
Many users had difficulty installing Bugzilla 4.0, 3.6.4, and 3.4.10,
due to a bug related to the "Math::Random::Secure" library. These
releases fix that bug among other issues.
Note that 4.1.2 is an unstable development release and should not
be used in production environments. However, we are getting very close
to feature freeze for 4.2, so now is the time to give us feedback on
4.1.2 if you want its behavior to change significantly before we
release.
Download
-------...
[ANN] Release of Bugzilla 4.4rc1, 4.2.4, 4.0.9, and 3.6.12 Today we are releasing 4.2.4, 4.0.9, 3.6.12, and the release
candidate 4.4rc1.
All of today's releases contain security fixes. We recommend
all Bugzilla administrators to read the Security Advisory linked below.
Bugzilla 4.2.4 is our latest stable release. It contains various
useful bug fixes and security fixes for the 4.2 branch.
Bugzilla 4.0.9 and 3.6.12 are security updates for the 4.0
branch and the 3.6 branch, respectively. 4.0.9 contains several
useful bug fixes and 3.6.12 contains one as well.
Bugzilla 4.4rc1 is our first Release Candidate for Bugzilla 4.4...
[ANN] Release of Bugzilla 4.5.3, 4.4.3, 4.2.8, and 4.0.12 Today we are releasing 4.4.3, 4.2.8, 4.0.12, and the unstable
development snapshot 4.5.3.
All of today's releases contain security fixes. We recommend
all Bugzilla administrators to read the Security Advisory linked below.
Bugzilla 4.4.3 is our latest stable release. It contains various
useful bug fixes, performance improvements and security fixes for
the 4.4 branch.
Bugzilla 4.2.8 and 4.0.12 are security updates for the 4.2
branch and the 4.0 branches, respectively. 4.2.8 also contains
several bug fixes.
Note that 4.5.3 is an unstable development release a...
[ANN] Release of Bugzilla 4.3.1, 4.2.1, 4.0.6, and 3.6.9 Today we are releasing 4.2.1, 4.0.6, 3.6.9, and the unstable
development snapshot 4.3.1.
All of today's releases contain security fixes. We recommend
all Bugzilla administrators to read the Security Advisory linked below.
Bugzilla 4.2.1 is our latest stable release. It contains various
useful bug fixes, performance improvements and security fixes for
the 4.2 branch.
Bugzilla 4.0.6 and 3.6.9 are security updates for the 4.0
branch and the 3.6 branch, respectively.
Note that 4.3.1 is an unstable development release and should not
be used in production environ...
[ANN] Release of Bugzilla 4.1.3, 4.0.2, 3.6.6, and 3.4.12 Today we are releasing 4.0.2, 3.6.6, 3.4.12, and the unstable
development snapshot 4.1.3.
All of today's releases contain security fixes. We recommend
all Bugzilla administrators read the Security Advisory linked below.
4.0.2 is our latest stable release, containing various useful
bug fixes and performance improvements.
3.6.6 and 3.4.12 are security updates for those series.
Note that 4.1.3 is an unstable development release and should not
be used in production environments. We are feature-frozen at this
point, however, so the features you see in 4.1.3 shoul...
[ANN] Release of Bugzilla 5.0.2, 4.4.11, and 4.2.16 Today we are releasing 5.0.2, 4.4.11, and 4.2.16. All releases fix
two security issues found since the last releases.
Bugzilla 5.0.2 is our latest stable release. It contains several
important bug fixes for the 5.0 branch.
Bugzilla 4.4.11 and 4.2.16 are security fix updates for the 4.4
branch and the 4.2 branch, respectively.
Download
--------
Bugzilla is available at:
https://www.bugzilla.org/download/
Release Notes & Changes
-----------------------
Before installing or upgrading, you should read the Release Notes for
this version of Bugzilla:
5.0.2...
[ANN] Release of Bugzilla 4.3.3, 4.2.3, 4.0.8, and 3.6.11 Today we are releasing 4.2.3, 4.0.8, 3.6.11, and the unstable
development snapshot 4.3.3.
All of today's releases contain security fixes. We recommend
all Bugzilla administrators to read the Security Advisory linked below.
Bugzilla 4.2.3 is our latest stable release. It contains various
useful bug fixes and security fixes for the 4.2 branch.
Bugzilla 4.0.8 and 3.6.11 are security updates for the 4.0
branch and the 3.6 branch, respectively. Both also contain
one bug fix.
Note that 4.3.3 is an unstable development release and should not
be used in production envir...
[ANN] Release of Bugzilla 4.3.2, 4.2.2, 4.0.7, and 3.6.10 Today we are releasing 4.2.2, 4.0.7, 3.6.10, and the unstable
development snapshot 4.3.2.
All of today's releases contain security fixes. We recommend
all Bugzilla administrators to read the Security Advisory linked below.
Bugzilla 4.2.2 is our latest stable release. It contains various
useful bug fixes and security fixes for the 4.2 branch.
Bugzilla 4.0.7 and 3.6.10 are security updates for the 4.0
branch and the 3.6 branch, respectively. 4.0.7 also contains
several bug fixes.
Note that 4.3.2 is an unstable development release and should not
be used in producti...
[ANN] Release of Bugzilla 4.4 and 4.2.6 Today the Bugzilla Project is extremely proud to announce the release of
Bugzilla 4.4! It has been over a year since we released Bugzilla 4.2 on
February 2012, and this new major release comes with several new features and
improvements. This release contains major improvements to WebServices, which
were our main target in this release, a rewritten tagging system, a real MIME
type auto-detection for attachments, improved support for Oracle, performance
improvements and lots of other enhancements. In addition, we are also releasing
a bug fix update for the 4.2.x series.
Bugzilla 4....