CVE-2009-3125

Publication date 15 September 2009

Last updated 24 July 2024


Ubuntu priority

Description

SQL injection vulnerability in the Bug.search WebService function in Bugzilla 3.3.2 through 3.4.1, and 3.5, allows remote attackers to execute arbitrary SQL commands via unspecified parameters.

Read the notes from the security team

Status

Package Ubuntu Release Status
bugzilla 9.04 jaunty
Not affected
8.10 intrepid
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper
Not affected

Notes


jdstrand

only 3.3.2 through 3.4.1 are affected


Access our resources on patching vulnerabilities