![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.70264 |
Category: | FreeBSD Local Security Checks |
Title: | FreeBSD Ports: bugzilla |
Summary: | The remote host is missing an update to the system; as announced in the referenced advisory. |
Description: | Summary: The remote host is missing an update to the system as announced in the referenced advisory. Vulnerability Insight: The following package is affected: bugzilla CVE-2011-2379 Cross-site scripting (XSS) vulnerability in Bugzilla 2.4 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3, when Internet Explorer before 9 or Safari before 5.0.6 is used for Raw Unified mode, allows remote attackers to inject arbitrary web script or HTML via a crafted patch, related to content sniffing. CVE-2011-2380 Bugzilla 2.23.3 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 allows remote attackers to determine the existence of private group names via a crafted parameter during (1) bug creation or (2) bug editing. CVE-2011-2979 Bugzilla 4.1.x before 4.1.3 generates different responses for certain assignee queries depending on whether the group name is valid, which allows remote attackers to determine the existence of private group names via a custom search. NOTE: this vulnerability exists because of a CVE-2010-2756 regression. CVE-2011-2381 CRLF injection vulnerability in Bugzilla 2.17.1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 allows remote attackers to inject arbitrary e-mail headers via an attachment description in a flagmail notification. CVE-2011-2978 Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, 3.4.x before 3.4.12, 3.5.x, 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 does not prevent changes to the confirmation e-mail address (aka old_email field) for e-mail change notifications, which makes it easier for remote attackers to perform arbitrary address changes by leveraging an unattended workstation. CVE-2011-2977 Bugzilla 3.6.x before 3.6.6, 3.7.x, 4.0.x before 4.0.2, and 4.1.x before 4.1.3 on Windows does not delete the temporary files associated with uploaded attachments, which allows local users to obtain sensitive information by reading these files. NOTE: this issue exists because of a regression in 3.6. CVE-2011-2976 Cross-site scripting (XSS) vulnerability in Bugzilla 2.16rc1 through 2.22.7, 3.0.x through 3.3.x, and 3.4.x before 3.4.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving a BUGLIST cookie. Solution: Update your system with the appropriate patches or software upgrades. CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2011-2379 BugTraq ID: 49042 http://www.securityfocus.com/bid/49042 Debian Security Information: DSA-2322 (Google Search) http://www.debian.org/security/2011/dsa-2322 http://www.osvdb.org/74297 http://secunia.com/advisories/45501 XForce ISS Database: bugzilla-patch-attachments-xss(69033) https://exchange.xforce.ibmcloud.com/vulnerabilities/69033 Common Vulnerability Exposure (CVE) ID: CVE-2011-2380 http://www.osvdb.org/74298 http://www.osvdb.org/74299 XForce ISS Database: bugzilla-editing-info-disclosure(69034) https://exchange.xforce.ibmcloud.com/vulnerabilities/69034 Common Vulnerability Exposure (CVE) ID: CVE-2011-2979 XForce ISS Database: bugzilla-queries-info-disclosure(69166) https://exchange.xforce.ibmcloud.com/vulnerabilities/69166 Common Vulnerability Exposure (CVE) ID: CVE-2011-2381 http://www.osvdb.org/74300 XForce ISS Database: bugzilla-attachment-header-injection(69035) https://exchange.xforce.ibmcloud.com/vulnerabilities/69035 Common Vulnerability Exposure (CVE) ID: CVE-2011-2978 http://www.osvdb.org/74301 XForce ISS Database: bugzilla-account-sec-bypass(69036) https://exchange.xforce.ibmcloud.com/vulnerabilities/69036 Common Vulnerability Exposure (CVE) ID: CVE-2011-2977 http://www.osvdb.org/74302 XForce ISS Database: bugzilla-attachments-info-disc(69037) https://exchange.xforce.ibmcloud.com/vulnerabilities/69037 Common Vulnerability Exposure (CVE) ID: CVE-2011-2976 http://www.osvdb.org/74303 XForce ISS Database: bugzilla-buglist-xss(69038) https://exchange.xforce.ibmcloud.com/vulnerabilities/69038 |
Copyright | Copyright (C) 2011 E-Soft Inc. |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |