From 8bff0a3a4112165508701a4bb205b09ccb846c7b Mon Sep 17 00:00:00 2001 From: Reed Loden Date: Wed, 10 Nov 2010 18:11:10 -0800 Subject: [PATCH] Bug 591165: (CVE-2010-2761) [SECURITY] Bump minimum required version of CGI.pm to v3.50 in order to address header injection vulnerability. [r=mkanat a=mkanat] --- Bugzilla/Install/Requirements.pm | 9 +++------ 1 file changed, 3 insertions(+), 6 deletions(-) diff --git a/Bugzilla/Install/Requirements.pm b/Bugzilla/Install/Requirements.pm index bb078e9b9f..8a7939afbb 100644 --- a/Bugzilla/Install/Requirements.pm +++ b/Bugzilla/Install/Requirements.pm @@ -66,12 +66,9 @@ sub REQUIRED_MODULES { { package => 'CGI.pm', module => 'CGI', - # Perl 5.10 requires CGI 3.33 due to a taint issue when - # uploading attachments, see bug 416382. - # Require CGI 3.21 for -httponly support, see bug 368502. - version => (vers_cmp($perl_ver, '5.10') > -1) ? '3.33' : '3.21', - # CGI::Carp in 3.46 and 3.47 breaks Template Toolkit - blacklist => ['^3\.46$', '^3\.47$'], + # 3.50 fixes a security problem that affects Bugzilla. + # (bug 591165) + version => '3.50', }, { package => 'Digest-SHA', -- 2.47.2