https://bugzilla.redhat.com/show_bug.cgi?id=1295436
Bug ID: 1295436 Summary: CVE-2015-8508 bugzilla: cross-site scripting when generating a dependency graph Product: Security Response Component: vulnerability Keywords: Security Severity: medium Priority: medium Assignee: security-response-team@redhat.com Reporter: mprpic@redhat.com CC: bazanluis20@gmail.com, emmanuel@seyman.fr, itamar@ispbrasil.com.br, perl-devel@lists.fedoraproject.org
Upstream Bugzilla fixed the following issue:
During the generation of a dependency graph, the code for the HTML image map is generated locally if a local dot installation is used. With escaped HTML characters in a bug summary, it is possible to inject unfiltered HTML code in the map file which the CreateImagemap function generates. This could be used for a cross-site scripting attack.
This issue was fixed in versions 4.2.16, 4.4.11, and 5.0.2.
Upstream bug:
https://bugzilla.mozilla.org/show_bug.cgi?id=1221518
https://bugzilla.redhat.com/show_bug.cgi?id=1295436
Martin Prpic mprpic@redhat.com changed:
What |Removed |Added ---------------------------------------------------------------------------- Depends On| |1295437
--- Comment #1 from Martin Prpic mprpic@redhat.com ---
Created bugzilla tracking bugs for this issue:
Affects: fedora-all [bug 1295437]
Referenced Bugs:
https://bugzilla.redhat.com/show_bug.cgi?id=1295437 [Bug 1295437] CVE-2015-8508 bugzilla: cross-site scripting when generating a dependency graph [fedora-all]
https://bugzilla.redhat.com/show_bug.cgi?id=1295436 Bug 1295436 depends on bug 1295437, which changed state.
Bug 1295437 Summary: CVE-2015-8508 bugzilla: cross-site scripting when generating a dependency graph [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1295437
What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |CLOSED Resolution|--- |EOL
perl-devel@lists.fedoraproject.org