CVE-2008-4437
Published: 3 October 2008
Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.
Notes
Author | Note |
---|---|
jdstrand | per stefanlsd, Dapper not affected |
Priority
Status
Package | Release | Status |
---|---|---|
bugzilla Launchpad, Ubuntu, Debian |
dapper |
Not vulnerable
|
feisty |
Ignored
(end of life, was needed)
|
|
gutsy |
Released
(2.22.1-2.2ubuntu1.7.10.1)
|
|
hardy |
Released
(2.22.1-2.2ubuntu1.8.04.1)
|
|
intrepid |
Released
(3.0.4.1-2ubuntu1.1)
|
|
upstream |
Released
(3.0.5)
|
|
Patches: other: https://bugzilla.mozilla.org/show_bug.cgi?id=437169 debdiff: http://launchpad.net/bugs/281915 |