Closed Bug 309863 Opened 19 years ago Closed 19 years ago

Security Advisory for 2.18.4, 2.20, and 2.21.1

Categories

(Bugzilla :: bugzilla.org, defect)

2.18.3
defect
Not set
blocker

Tracking

()

RESOLVED FIXED

People

(Reporter: mkanat, Assigned: mkanat)

References

Details

Attachments

(1 file, 3 obsolete files)

We'll need a SecAdv for these versions, since we've discovered some security bugs.

If somebody other than me wants to write it, that would be OK. The format for
writing a security advisory is on the "How To Release Bugzilla" page, on
bugzilla.org's Developer Resources page.
bug 308662 is ready for checkin. bug 308256 is still waiting for review (myk?).
Status: NEW → ASSIGNED
Attached file Typo fixed (obsolete) β€”
Fixed a typo. Thanks to Vlad.
Attachment #197333 - Attachment is obsolete: true
Comment on attachment 197334 [details]
Typo fixed


>Issue 2
>-------
>Class:       Information Leak
>Versions:    2.19.1 - 2.20rc1, 2.21

2.20rc2 is also affected. Else it looks good. r+ from me ;)
Attached file v3 (obsolete) β€”
Ah, thanks LpSolit. :-) Fixed that typo.
Attachment #197334 - Attachment is obsolete: true
Attached file v4 β€”
justdave had some feedback on the security list, about mentioning that these
bugs don't affect 2.16. I've done that, now.
Attachment #197403 - Attachment is obsolete: true
OK, advisory sent to announce, mozilla-webtools, and BugTraq.
Group: webtools-security
Status: ASSIGNED → RESOLVED
Closed: 19 years ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: