CVE-2008-4437

Publication date 3 October 2008

Last updated 24 July 2024


Ubuntu priority

Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.

Read the notes from the security team

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
bugzilla 8.10 intrepid
Fixed 3.0.4.1-2ubuntu1.1
8.04 LTS hardy
Fixed 2.22.1-2.2ubuntu1.8.04.1
7.10 gutsy
Fixed 2.22.1-2.2ubuntu1.7.10.1
7.04 feisty Ignored end of life, was needed
6.06 LTS dapper
Not affected

Notes


jdstrand

per stefanlsd, Dapper not affected

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
bugzilla