]> git.ipfire.org Git - thirdparty/bugzilla.git/commitdiff
Bug 802204 (CVE-2012-4197): [SECURITY] Marking an attachment you cannot see as obsole...
authorFrédéric Buclin <LpSolit@gmail.com>
Tue, 13 Nov 2012 17:21:35 +0000 (18:21 +0100)
committerFrédéric Buclin <LpSolit@gmail.com>
Tue, 13 Nov 2012 17:21:35 +0000 (18:21 +0100)
r=gerv a=LpSolit

Bugzilla/Attachment.pm

index 8f296d263daabbdb401ecf028fb7a229d04be5b4..e7e707b985c0b58a5573f6f8d85f6301f8ee267c 100644 (file)
@@ -765,11 +765,8 @@ sub validate_obsolete {
         $attachment->validate_can_edit($bug->product_id)
           || ThrowUserError('illegal_attachment_edit', { attach_id => $attachment->id });
 
-        $vars->{'description'} = $attachment->description;
-
         if ($attachment->bug_id != $bug->bug_id) {
             $vars->{'my_bug_id'} = $bug->bug_id;
-            $vars->{'attach_bug_id'} = $attachment->bug_id;
             ThrowUserError('mismatched_bug_ids_on_obsolete', $vars);
         }