|
From: Michael L. <inc...@my...> - 2002-10-02 13:30:30
|
Kelledin, We may be running Bugzilla, but is anyone using Bugzilla...just like me asking for IOS to be put up on CVS; Enrico has uploaded a installer program to his site on inceptionos.org but no one has comitted anything to CVS. :( Michael On Tue, 1 Oct 2002 14:21:00 -0500, "Kelledin" <kel...@sk...> said: > Thought I'd pass this on, since we're running bugzilla ourselves > on inceptionos.org. ;) > > ---------- Forwarded Message ---------- > > Subject: [BUGZILLA] Security Advisory > Date: Tue, 1 Oct 2002 12:50:46 -0400 > From: David Miller <jus...@sy...> > To: bu...@se..., ann...@bu..., > moz...@mo... > > Bugzilla Security Advisory > > October 1st, 2002 > > All Bugzilla installations are advised to upgrade to the latest > versions of Bugzilla, 2.14.4 and 2.16.1, both released today. > Security issues of varying importance have been fixed in both. > These vulnerabilities affect all previous 2.14 and 2.16 > releases. > > 2.14.x users are additionally encouraged to upgrade to 2.16.1 as > soon as possible, as the 2.14 branch will no longer be > maintained by the Bugzilla team beyond the end of this year. > > Individual patches to upgrade Bugzilla are available at > http://ftp.mozilla.org/pub/webtools/ > (however these patches are only valid for 2.14.3 and 2.16 > users). > > Full release downloads and CVS upgrade instructions are > available at http://www.bugzilla.org/download.html > > Complete bug reports for all the following bugs may be obtained > at http://bugzilla.mozilla.org/ > > The following security issues were fixed in both 2.14.4 and > 2.16.1: > > - Permissions leak when using "usebuggroups" and more than 47 > groups; permissions are granted to users in higher groups when > they shouldn't be. (bug 167485; comment 12 has additional > detection/recovery information) > http://bugzilla.mozilla.org/show_bug.cgi?id=167485#c12 > > - bugzilla_email_append.pl calls processmail insecurely; command > injection possible. > (bug 163024) > > The following additional security issue was fixed in 2.16.1: > > - Apostrophes are not properly handled during account creation; > SQL injection possible. > (bug 165221) > > General information about the Bugzilla bug-tracking system can > be found at http://www.bugzilla.org/ > > Comments and follow-ups can be directed to the > netscape.public.mozilla.webtools newsgroup or the > mozilla-webtools mailing list; > http://www.mozilla.org/community.html has directions for > accessing these forums. > -- > Dave Miller Project Leader, Bugzilla Bug Tracking System > Lead Software Engineer/System Administrator, Syndicomm Online > http://www.syndicomm.com/ http://www.bugzilla.org/ > > ------------------------------------------------------- > > -- > Kelledin > "If a server crashes in a server farm and no one pings it, does > it still cost four figures to fix?" > > > > ------------------------------------------------------- > This sf.net email is sponsored by: DEDICATED SERVERS only $89! > Linux or FreeBSD, FREE setup, FAST network. Get your own server > today at http://www.ServePath.com/indexfm.htm > _______________________________________________ > Maxlinux-devel mailing list > Max...@li... > https://lists.sourceforge.net/lists/listinfo/maxlinux-devel > -- Michael Lauzon Founder & Lead Project Manager InceptionOS Project http://www.inceptionos.org/ mi...@in... -- http://fastmail.fm/ - Access your email from home and the web |
|
From: Michael L. <inc...@my...> - 2002-10-04 14:07:50
|
Terry, Not meant to offend, documents are one thing...we need the basic IOS itself put up on CVS as well; and then announce that it is up on a site like LinuxToday.com and Slashdot, etc. In that way I see us getting more Developers and whatnot because then we'll have something to show; because as I think some people see it IOS is vapourware at the moment until we get it up somewhere. Michael On Wed, 2 Oct 2002 18:05:44 +0100, "Terry Churchill" <te...@do...> said: > Michael Lauzon <inc...@my...> Said: > > > We may be running Bugzilla, but is anyone using Bugzilla...just like me > > asking for IOS to be put up on CVS; Enrico has uploaded a installer > > program to his site on inceptionos.org but no one has comitted anything > > to CVS. :( > > There is at least 1 doc in CVS atm, but due to illness & real life ATM > I'm > having a hard time finding time to install viewcvs & update bugzilla. > > I hope to be able to devote a few hours to tidying up loose ends within > the > next day or two... > > HTH > -- > Terry Churchill : http://www.doc-linux.co.uk/ > > "The people united can never be ignited!"- Sgt. Colon, Ankh-Morpork > Watch > -- http://fastmail.fm - Email service worth paying for. Try it for free |
|
From: Terry C. <te...@do...> - 2002-10-02 17:06:04
|
Michael Lauzon <inc...@my...> Said: > We may be running Bugzilla, but is anyone using Bugzilla...just like me > asking for IOS to be put up on CVS; Enrico has uploaded a installer > program to his site on inceptionos.org but no one has comitted anything > to CVS. :( There is at least 1 doc in CVS atm, but due to illness & real life ATM I'm having a hard time finding time to install viewcvs & update bugzilla. I hope to be able to devote a few hours to tidying up loose ends within the next day or two... HTH -- Terry Churchill : http://www.doc-linux.co.uk/ "The people united can never be ignited!"- Sgt. Colon, Ankh-Morpork Watch |