]>
git.ipfire.org Git - thirdparty/bugzilla.git/log
Dave Lawrence [Wed, 28 Dec 2011 23:02:39 +0000 (18:02 -0500)]
Bump version number for 3.4.13
Frédéric Buclin [Wed, 28 Dec 2011 22:19:23 +0000 (23:19 +0100)]
Bug 711714: (CVE-2011-3667) [SECURITY] The User.offer_account_by_email WebService method lets you create new user accounts independently of the value of Bugzilla::Auth::Verify::*::user_can_create_account
r=dkl a=LpSolit
Byron Jones [Wed, 28 Dec 2011 21:48:20 +0000 (16:48 -0500)]
Bug 697699 - (CVE-2011-3657) [SECURITY] XSS when viewing new charts or tabular and graphical reports in debug mode
r=gerv, a=LpSolit
Frédéric Buclin [Mon, 26 Dec 2011 10:39:05 +0000 (11:39 +0100)]
Bug 713343: Release notes for Bugzilla 3.4.13
r=wicked a=LpSolit
Frédéric Buclin [Thu, 8 Dec 2011 22:52:39 +0000 (23:52 +0100)]
Bug 707170: Several features about custom fields are missing in the documentation
r=dkl a=LpSolit
Matt Selsky [Mon, 5 Dec 2011 21:31:44 +0000 (22:31 +0100)]
Bug 692354: Incorrect parameter type in WebServices documentation for Bug.add_comment
r/a=mkanat
Frédéric Buclin [Fri, 2 Dec 2011 16:38:54 +0000 (17:38 +0100)]
Bug 591610: Custom field doc doesn't include 'Bug ID' type
r=timello a=LpSolit
Matt Selsky [Wed, 16 Nov 2011 16:55:32 +0000 (17:55 +0100)]
Bug 531257: Wrong error codes in WebServices documentation
r=gerv a=LpSolit
Matt Selsky [Sat, 15 Oct 2011 12:24:00 +0000 (14:24 +0200)]
Bug 445804: Suggested crontab configuration opens security hole
r/a=mkanat
Max Kanat-Alexander [Sat, 6 Aug 2011 00:15:42 +0000 (17:15 -0700)]
Bump the version number post-release.
Max Kanat-Alexander [Fri, 5 Aug 2011 00:10:04 +0000 (17:10 -0700)]
Bump version number for 3.4.12.
https://bugzilla.mozilla.org/show_bug.cgi?id=660531
Byron Jones [Thu, 4 Aug 2011 20:49:51 +0000 (22:49 +0200)]
Bug 670868: (CVE-2011-2978) [SECURITY] Account preferences page trusts user-modifiable field for obtaining current e-mail address
r/a=LpSolit
Byron Jones [Thu, 4 Aug 2011 20:38:53 +0000 (22:38 +0200)]
Bug 637981: (CVE-2011-2379) [SECURITY] "Raw Unified" patch diffs can cause XSS on this domain in IE 6-8 and Safari
r/a=LpSolit
Frédéric Buclin [Thu, 4 Aug 2011 20:14:36 +0000 (22:14 +0200)]
Bug 653477: (CVE-2011-2380) [SECURITY] Group names can be guessed when creating or editing a bug
r=dkl a=LpSolit
Max Kanat-Alexander [Thu, 4 Aug 2011 20:02:26 +0000 (22:02 +0200)]
Bug 660053: (CVE-2011-2976) [SECURITY] If a BUGLIST cookie is compromised, it can be used to XSS show_bug.cgi and inject HTML into <head>
r/a=LpSolit
Frédéric Buclin [Thu, 4 Aug 2011 19:25:13 +0000 (12:25 -0700)]
Bug 657158 - (CVE-2011-2381) [SECURITY] Request email headers for attachment containing newline are corrupt
[r=glob a=LpSolit]
Frédéric Buclin [Tue, 2 Aug 2011 22:44:25 +0000 (00:44 +0200)]
Bug 675751: Release notes for Bugzilla 3.4.12
r/a=mkanat
Max Kanat-Alexander [Thu, 28 Apr 2011 03:52:44 +0000 (20:52 -0700)]
Bump the version number post-release.
Max Kanat-Alexander [Thu, 28 Apr 2011 02:16:46 +0000 (19:16 -0700)]
Bump version number for 3.4.11.
https://bugzilla.mozilla.org/show_bug.cgi?id=652474
Max Kanat-Alexander [Thu, 28 Apr 2011 00:24:59 +0000 (17:24 -0700)]
Bug 653275 - Release Notes for Bugzilla 3.4.11
r=LpSolit, a=LpSolit
Max Kanat-Alexander [Wed, 27 Apr 2011 22:03:41 +0000 (15:03 -0700)]
Bug 646578: Remove the usage of Math::Random::Secure, as it is too difficult
to install on older branches.
r=LpSolit, a=mkanat
Matt Selsky [Tue, 22 Mar 2011 20:16:00 +0000 (16:16 -0400)]
Bug 311392 - Typos and proper name of Red Hat's stuff
author=Matt Selksy <selsky_at_columbia_dot_edu>, r=dkl, a=mkanat
David Lawrence [Fri, 18 Mar 2011 21:01:19 +0000 (17:01 -0400)]
Bug 586011 - Change references to 'DarwinPorts' to 'MacPorts' (proper project name)
author=Matt Selsky <selsky_at_columbia_dot_edu>, r=dkl,a=mkanat
Max Kanat-Alexander [Mon, 14 Feb 2011 07:44:02 +0000 (23:44 -0800)]
Bug 633422: Fix the documentation for User.get's include_disabled parameter
and make User.get check that its required parameters are passed.
r=LpSolit, a=mkanat
Max Kanat-Alexander [Tue, 25 Jan 2011 01:48:52 +0000 (17:48 -0800)]
Bump the version number post-release.
Max Kanat-Alexander [Mon, 24 Jan 2011 23:35:12 +0000 (15:35 -0800)]
Bump version number for 3.4.10.
Max Kanat-Alexander [Mon, 24 Jan 2011 21:49:06 +0000 (13:49 -0800)]
Bug 619594: (CVE-2010-4568) [SECURITY] Improve the randomness of
generate_random_password, to protect against an account compromise issue
and other critical vulnerabilities.
r=LpSolit, a=LpSolit
https://bugzilla.mozilla.org/show_bug.cgi?id=621591
David Lawrence [Mon, 24 Jan 2011 19:20:21 +0000 (14:20 -0500)]
Bug 621105 - [SECURITY] Voting lacks CSRF protection
r=mkanat,a=LpSolit
Frédéric Buclin [Mon, 24 Jan 2011 18:38:50 +0000 (19:38 +0100)]
Bug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking for javascript: or data: URLs in the URL field can be evaded with prefixed whitespace
and
Bug 628034: (CVE-2011-0048) [SECURITY] For not-logged-in users, the URL field doesn't safeguard against javascript: or data: URLs
r=dkl a=LpSolit
Reed Loden [Mon, 24 Jan 2011 18:15:04 +0000 (10:15 -0800)]
Bug 621572: (CVE-2010-4572) [SECURITY] chart.cgi vulnerable to header-injection due to use of |print "Location:"| instead of $cgi->redirect
[r=mkanat a=LpSolit]
Frédéric Buclin [Mon, 24 Jan 2011 17:29:38 +0000 (18:29 +0100)]
Bug 621110: [SECURITY] Quips (adding/approving/deleting) lacks CSRF protection
r=dkl a=LpSolit
Frédéric Buclin [Mon, 24 Jan 2011 17:17:45 +0000 (18:17 +0100)]
Bug 621108: [SECURITY] Creating/editing charts lacks CSRF protection
r=dkl a=LpSolit
Max Kanat-Alexander [Mon, 24 Jan 2011 04:13:37 +0000 (20:13 -0800)]
Bug 627930 - Release Notes for Bugzilla 3.4.10
r=LpSolit
Reed Loden [Fri, 21 Jan 2011 21:17:43 +0000 (13:17 -0800)]
Bug 591165: (CVE-2010-4411) [SECURITY] Bump minimum required version of CGI.pm to v3.51 in order to address header injection vulnerability.
[r=mkanat a=mkanat]
Frédéric Buclin [Sat, 27 Nov 2010 21:06:43 +0000 (22:06 +0100)]
Bug 416784: In PostgreSQL 8.1 and newer, createuser takes the argument -R instead of -A
r=manu a=LpSolit
Reed Loden [Thu, 11 Nov 2010 02:40:08 +0000 (18:40 -0800)]
Bug 591165: (CVE-2010-2761) [SECURITY] Add CGI.pm v3.50 as an optional module in order to address header injection vulnerability.
[r=mkanat a=mkanat]
Max Kanat-Alexander [Wed, 3 Nov 2010 01:35:51 +0000 (18:35 -0700)]
Bump the version number post-release.
Max Kanat-Alexander [Wed, 3 Nov 2010 00:38:59 +0000 (17:38 -0700)]
Bump version number for 3.4.9.
https://bugzilla.mozilla.org/show_bug.cgi?id=604255
Byron Jones [Tue, 2 Nov 2010 23:22:45 +0000 (00:22 +0100)]
Bug 600464: (CVE-2010-3172) [SECURITY] Content/Header injection due to non-random multipart/x-mixed-replace boundary
r=mkanat a=LpSolit
Frédéric Buclin [Tue, 2 Nov 2010 23:12:13 +0000 (00:12 +0100)]
Bug 419014: (CVE-2010-3764) [SECURITY] Old charts are not project specific, and product names are viewable in graphs/
r=wurblzap a=LpSolit
Max Kanat-Alexander [Mon, 1 Nov 2010 06:52:34 +0000 (23:52 -0700)]
Bug 608645: Release Notes for Bugzilla 3.4.9
r=LpSolit, a=LpSolit
A. Shimono (himorin) [Sun, 19 Sep 2010 00:11:32 +0000 (02:11 +0200)]
Bug 589547: Wrong description for editing a flag
r/a=LpSolit
A. Shimono (himorin) [Sun, 19 Sep 2010 00:00:50 +0000 (02:00 +0200)]
Bug 589525: fix typo
r/a=LpSolit
Max Kanat-Alexander [Fri, 6 Aug 2010 02:30:18 +0000 (19:30 -0700)]
Bump version number post-release.
Max Kanat-Alexander [Fri, 6 Aug 2010 01:14:04 +0000 (18:14 -0700)]
Bump the version number for 3.4.8.
https://bugzilla.mozilla.org/show_bug.cgi?id=580206
Frédéric Buclin [Wed, 4 Aug 2010 22:15:55 +0000 (00:15 +0200)]
Bug 583690: (CVE-2010-2759) [SECURITY][PostgreSQL] Bugzilla crashes when viewing a bug if a comment contains 'bug <num>' or 'attachment <num>' where <num> is greater than the max allowed integer
r=mkanat a=LpSolit
Frédéric Buclin [Wed, 4 Aug 2010 21:58:19 +0000 (23:58 +0200)]
Bug 577139: (CVE-2010-2758) [SECURITY] request.cgi and duplicates.cgi let you know whether a product exists or not
r=mkanat a=LpSolit
Frédéric Buclin [Wed, 4 Aug 2010 21:46:06 +0000 (23:46 +0200)]
Bug 450013: (CVE-2010-2757) [SECURITY] Can sudo a user without sending email
r=glob a=LpSolit
Frédéric Buclin [Wed, 4 Aug 2010 21:33:33 +0000 (23:33 +0200)]
Bug 417048: (CVE-2010-2756) [SECURITY] Boolean charts let me query for users being in any given group
r=mkanat a=LpSolit
Max Kanat-Alexander [Wed, 4 Aug 2010 18:15:10 +0000 (11:15 -0700)]
Bug 584428: Release Notes for Bugzilla 3.4.8
r=LpSolit
Frédéric Buclin [Thu, 15 Jul 2010 11:07:48 +0000 (13:07 +0200)]
Bug 455585: Installation docs should recommend using package management instead of CPAN
r=glob
Frédéric Buclin [Thu, 15 Jul 2010 10:51:19 +0000 (12:51 +0200)]
Bug 193193: Better explain what the checkboxes in Edit Users-Group Access/Privileges are for
r=glob
Frédéric Buclin [Thu, 15 Jul 2010 10:34:53 +0000 (12:34 +0200)]
Bug 472452: Rephrase documentation about deleting custom fields
r=glob
Frédéric Buclin [Tue, 13 Jul 2010 23:11:42 +0000 (01:11 +0200)]
Bug 536183: Docs claim bug lifecycle is "hard-coded" despite that's no longer true
r=gerv a=mkanat
Frédéric Buclin [Tue, 13 Jul 2010 22:37:36 +0000 (00:37 +0200)]
Bug 577851: config.cgi crashes in 3.4.7, due to Bugzilla::Product::preload (backout of bug 553255)
r/a=mkanat
Frédéric Buclin [Tue, 13 Jul 2010 08:38:14 +0000 (10:38 +0200)]
Bug 236651: Remove obsolete instructions from the "2.1.5 Perl Modules" section
r=reed
Max Kanat-Alexander [Thu, 24 Jun 2010 23:15:18 +0000 (16:15 -0700)]
Bump version number post-release
Max Kanat-Alexander [Thu, 24 Jun 2010 20:44:26 +0000 (13:44 -0700)]
Bump the version number for 3.4.7.
https://bugzilla.mozilla.org/show_bug.cgi?id=559988
Max Kanat-Alexander [Thu, 24 Jun 2010 17:09:26 +0000 (10:09 -0700)]
Bug 309952: (CVE-2010-1204) [SECURITY] Protect boolean chart searches for
time-tracking fields from being used by users who are not in the
timetrackinggroup.
r=LpSolit, a=mkanat
Max Kanat-Alexander [Tue, 22 Jun 2010 04:08:55 +0000 (21:08 -0700)]
Bug 566198: Release Notes for Bugzilla 3.4.7
r=LpSolit, a=mkanat
Frédéric Buclin [Thu, 8 Apr 2010 10:32:16 +0000 (12:32 +0200)]
Bug 284650: Beginning a chart name with an "_" (underscore) causes errors
r=mkanat a=LpSolit
Frédéric Buclin [Wed, 7 Apr 2010 01:02:55 +0000 (03:02 +0200)]
Bug 557686: PostgreSQL crashes when deleting a custom field of type Date/Time
r=mkanat a=LpSolit
Frédéric Buclin [Tue, 6 Apr 2010 23:58:46 +0000 (01:58 +0200)]
Bug 557495: PostgreSQL crashes when deleting a custom field of type BugID
r/a=mkanat
Frank Becker [Fri, 2 Apr 2010 12:49:22 +0000 (14:49 +0200)]
Bug 515515: For clients, mid-air collision results when user's timezone preference differs from server's
r/a=mkanat
Tiago Mello [Mon, 29 Mar 2010 12:36:02 +0000 (14:36 +0200)]
Bug 548327: Administration page should have hooks to extend the admin links
r/a=mkanat
Guy Pyrzak [Sun, 28 Mar 2010 21:45:24 +0000 (14:45 -0700)]
Bug 548975: Under trunk Firefox builds with Direct2D enabled on Windows,
<dt> tags were overly bold
r=mkanat, a=mkanat
Reed Loden [Sun, 28 Mar 2010 06:30:56 +0000 (01:30 -0500)]
Bug 549814 - "Internal error when using login fields in header/footer after visiting token.cgi URL"
[r=mkanat a=mkanat]
Reed Loden [Sun, 28 Mar 2010 04:38:48 +0000 (23:38 -0500)]
Bug 533927 - "email address domain filtering is applying to non-email fields in the history"
[r=LpSolit a=LpSolit]
Max Kanat-Alexander [Thu, 18 Mar 2010 13:56:55 +0000 (06:56 -0700)]
Bug 553267: Allow specifying that you don't want flag data, for config.cgi
r=gerv, a=mkanat
Max Kanat-Alexander [Thu, 18 Mar 2010 13:17:35 +0000 (06:17 -0700)]
Bug 553255: Make config.cgi use Bugzilla::Product::preload, for a small
performance improvement
r=gerv, a=mkanat
Max Kanat-Alexander [Wed, 17 Mar 2010 08:38:32 +0000 (01:38 -0700)]
Bug 538705: Prevent database connections from timing out during long
jobqueue.pl runs.
r=LpSolit, a=mkanat
Frédéric Buclin [Mon, 15 Mar 2010 14:27:10 +0000 (15:27 +0100)]
Bug 552349: A lot of errors are thrown when an Atom feed queries Bugzilla
r/a=mkanat
Max Kanat-Alexander [Sun, 14 Mar 2010 00:35:31 +0000 (16:35 -0800)]
Bug 498309: Speed up show_bug when there are many comments by caching the
results of get_text calls in Bugzilla::Template, and removing the call
to field-descs.none.tmpl from format_comment.txt.tmpl.
r=LpSolit, a=LpSolit
Max Kanat-Alexander [Tue, 9 Mar 2010 17:59:30 +0000 (09:59 -0800)]
Bump version number post-release.
Max Kanat-Alexander [Tue, 9 Mar 2010 06:53:37 +0000 (22:53 -0800)]
Bug 374632: A separate script just to fix file/directory permissions
r=mkanat, a=mkanat (module owner)
Max Kanat-Alexander [Tue, 9 Mar 2010 04:31:31 +0000 (20:31 -0800)]
Bug 551104: Don't install DBD::Pg when using install-module.pl --all unless
the PostgreSQL devel files are actually installed.
r=mkanat, a=mkanat (module owner)
Max Kanat-Alexander [Mon, 8 Mar 2010 07:49:28 +0000 (23:49 -0800)]
Bump version number for 3.4.6.
https://bugzilla.mozilla.org/show_bug.cgi?id=547465
Max Kanat-Alexander [Mon, 8 Mar 2010 02:46:49 +0000 (18:46 -0800)]
Remove CVS "$Id" markers in files. The CVS mirror of bzr was showing
the docs' about.xml and installation.xml being modified on every commit
because of these markers, and the rest of them are simply unnecessary.
Max Kanat-Alexander [Mon, 8 Mar 2010 02:34:13 +0000 (18:34 -0800)]
Bug 549482: Release Notes for Bugzilla 3.4.6
r=LpSolit
Frédéric Buclin [Mon, 8 Mar 2010 01:28:54 +0000 (02:28 +0100)]
Bug 549588: Documentation incorrectly refers to localconfig for priorities, severities, platforms and operating systems
r=glob
Frédéric Buclin [Mon, 8 Mar 2010 01:15:47 +0000 (02:15 +0100)]
Bug 549671: The "1.3. New Versions" section is out-of-date
r=glob
Frédéric Buclin [Mon, 8 Mar 2010 00:51:56 +0000 (01:51 +0100)]
Bug 542464: Dependency graphs cannot be displayed when bug summaries contain UTF8 characters
r/a=mkanat
Frédéric Buclin [Sun, 7 Mar 2010 16:37:03 +0000 (17:37 +0100)]
Bug 549685: Update the list of required and optional Perl modules
r=ghendricks a=LpSolit
David Lawrence [Fri, 5 Mar 2010 18:49:28 +0000 (13:49 -0500)]
Bug 513989 - large search query causing internal server error (500) but valid redirect 302 returned
Decreased CGI_URI_LIMIT to 8000 instead of 10000
a=mkanat
Dave Lawrence [Wed, 3 Mar 2010 21:23:07 +0000 (16:23 -0500)]
Bug 513989 - large search query causing internal server error (500) but valid redirect 302 returned
r=mkanat, a=mkanat
Max Kanat-Alexander [Sun, 28 Feb 2010 23:59:14 +0000 (15:59 -0800)]
Bug 548933: The "Mark as Duplicate" link was changing bugs to RESOLVED FIXED
r=pyrzak, a=mkanat
Max Kanat-Alexander [Sun, 28 Feb 2010 23:18:33 +0000 (15:18 -0800)]
Bug 474738: Make all of the "not" search types show up in search descriptions
r=LpSolit, a=LpSolit
Reed Loden [Sun, 28 Feb 2010 20:15:34 +0000 (14:15 -0600)]
Bug 537834 - "Buglist results using atom ctype do not display users with empty real names"
[r=LpSolit a=LpSolit]
Reed Loden [Sun, 28 Feb 2010 20:09:41 +0000 (14:09 -0600)]
Bug 549177 - "Typo in admin.cgi page header"
[r=LpSolit a=LpSolit]
Max Kanat-Alexander [Wed, 24 Feb 2010 23:41:34 +0000 (15:41 -0800)]
Some lines in the release notes started with a "[% terms" item but didn't
have [%+ on them, so the words would get crunched together, like "thisBugzilla".
Guy Pyrzak [Thu, 18 Feb 2010 19:01:41 +0000 (20:01 +0100)]
Bug 546763: Extra spaces when copying bug header
r=reed a=mkanat
Guy Pyrzak [Thu, 18 Feb 2010 18:57:54 +0000 (19:57 +0100)]
Bug 546719: When reopening a Resolved Duplicated bug in IE, JS error stops the correct page behavior
r/a=mkanat
Frédéric Buclin [Thu, 18 Feb 2010 00:19:45 +0000 (01:19 +0100)]
Bug 533018: "Confirm match" displays full email address to logged-out users in request.cgi
r/a=mkanat
Gordon P. Hemsley [Wed, 17 Feb 2010 22:38:46 +0000 (14:38 -0800)]
Bug 546338: Fix an unclosed <a> tag in fields.html
r=mkanat, a=mkanat
Max Kanat-Alexander [Wed, 17 Feb 2010 22:07:00 +0000 (14:07 -0800)]
Bug 538211: Make value-controlled and visibility-controlled fields behave
correctly on enter_bug.cgi when the user uses a bookmarkable template to
pre-fill values in the controller.
r=LpSolit, a=LpSolit
Reed Loden [Thu, 11 Feb 2010 19:34:50 +0000 (13:34 -0600)]
Bug 545695 - "show_bug.cgi: Use of uninitialized value"
[r=LpSolit a=LpSolit]
Max Kanat-Alexander [Wed, 10 Feb 2010 05:16:00 +0000 (21:16 -0800)]
Bug 545277: Closed bugs were always marked as FIXED in the resolution
<select> when show_bug.cgi was loaded
r=LpSolit, a=mkanat
Max Kanat-Alexander [Mon, 8 Feb 2010 23:44:48 +0000 (15:44 -0800)]
Bug 520993: If the "FIXED" resolution was a visibility or value controller,
then controlled fields weren't properly changing when the status changed to
RESOLVED and "FIXED" appeared as the first value in the Resolution field.
r=LpSolit, a=mkanat
Max Kanat-Alexander [Mon, 8 Feb 2010 04:04:28 +0000 (20:04 -0800)]
Bug 544812: Template hooks for reports/menu.html.tmpl
r=mkanat, a=mkanat (module owner)
Frédéric Buclin [Sat, 6 Feb 2010 18:04:07 +0000 (19:04 +0100)]
Bug 515568: handle_login() doesn't check $@ after eval
r/a=mkanat