https://bugzilla.redhat.com/show_bug.cgi?id=1336671
Bug ID: 1336671 Summary: CVE-2016-2803 bugzilla: Cross-site-scripting in dependency graphs Product: Security Response Component: vulnerability Keywords: Security Severity: medium Priority: medium Assignee: security-response-team@redhat.com Reporter: anemec@redhat.com CC: bazanluis20@gmail.com, emmanuel@seyman.fr, itamar@ispbrasil.com.br, perl-devel@lists.fedoraproject.org, xavier@bachelot.org
A vulnerability was found in the bugzilla application. Due to an incorrect parsing of the image map generated by the dot script, a specially crafted bug summary could trigger XSS in dependency graphs.
External references:
https://bugzilla.mozilla.org/show_bug.cgi?id=1253263
References:
http://seclists.org/bugtraq/2016/May/72
Upstream fix:
https://git.mozilla.org/?p=bugzilla/bugzilla.git;a=commitdiff;h=dd61903