CVE-2011-0048

Priority
Medium
Description
Bugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x
before 4.0rc2 creates a clickable link for a (1) javascript: or (2) data:
URI in the URL (aka bug_file_loc) field, which allows remote attackers to
conduct cross-site scripting (XSS) attacks against logged-out users via a
crafted URI.
References
Package
Upstream:released (3.2.10, 3.4.10, 3.6.4)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):DNE (dropped by debian)
Ubuntu 12.10 (Quantal Quetzal):DNE (dropped by debian)
Ubuntu 13.04 (Raring Ringtail):DNE (dropped by debian)
Ubuntu 13.10 (Saucy Salamander):DNE (dropped by debian)
Ubuntu 14.04 LTS (Trusty Tahr):DNE (dropped by debian)
Patches:
Vendor:http://www.debian.org/security/2011/dsa-2322
More Information

Valid XHTML 1.0 Strict

Updated: 2013-12-20 21:16:27 UTC (commit 7585)