Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.59806
Category:Fedora Local Security Checks
Title:Fedora Core 7 FEDORA-2007-2299 (bugzilla)
Summary:NOSUMMARY
Description:Description:

The remote host is missing an update to bugzilla
announced via advisory FEDORA-2007-2299.

Bugzilla is a popular bug tracking system used by multiple open source
projects. It requires a database engine installed - either MySQL or
PostgreSQL. Without one of these database engines, Bugzilla will not work.

Update Information:

Update to 3.0.2 for upstream vulnerabilities
ChangeLog:

* Mon Sep 24 2007 John Berninger - 3.0.2-0
- update to 3.0.2 - bz 299981
* Mon Aug 27 2007 John Berninger - 3.0.1-0
- update to 3.0.1 - bz 256021
* Fri May 18 2007 John Berninger - 3.0-2
- update Requires for bz's 241037, 241206
* Fri May 18 2007 John Berninger - 3.0-1
- update to upstream version 3.0
- add new dependencies on mod_perl, perl-SOAP-Lite
- refactor patch(es) to change paths for read-only /usr
References:

[ 1 ] Bug #299981 - CVE-2007-5038 Security Advisory for Bugzilla 3.0.1 and 3.1.1
https://bugzilla.redhat.com/show_bug.cgi?id=299981
[ 2 ] CVE-2007-5038
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5038
Updated packages:

aecd92525ac4a385c56c513040df1a0a47713b49 bugzilla-doc-3.0.2-0.fc7.noarch.rpm
297bbc3674d344aa35bc25ff57751c66dfdf0974 bugzilla-contrib-3.0.2-0.fc7.noarch.rpm
8710ced9d1ce2ad42aa9542db08a4cc7e535f5cb bugzilla-3.0.2-0.fc7.noarch.rpm
778a2b86c99d2e1d2d99b2ca819effa7263de7b3 bugzilla-3.0.2-0.fc7.src.rpm

This update can be installed with the yum update program. Use
su -c 'yum update bugzilla'
at the command line. For more information, refer to Managing Software
with yum, available at http://docs.fedoraproject.org/yum/.

Solution: Apply the appropriate updates.

http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2007-2299

Risk factor : High

CVSS Score:
7.5

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-5038
BugTraq ID: 25725
http://www.securityfocus.com/bid/25725
Bugtraq: 20070919 Security Advisory for Bugzilla 3.0.1 and 3.1.1 (Google Search)
http://www.securityfocus.com/archive/1/480077/100/0/threaded
http://fedoranews.org/updates/FEDORA-2007-229.shtml
http://www.securitytracker.com/id?1018719
http://secunia.com/advisories/26848
http://secunia.com/advisories/26969
http://www.vupen.com/english/advisories/2007/3200
XForce ISS Database: bugzilla-offeraccount-security-bypass(36692)
https://exchange.xforce.ibmcloud.com/vulnerabilities/36692
CopyrightCopyright (c) 2007 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.