Latest news
All users of Bugzilla who are currently using version 2.15 checked out of cvs prior to 15 December 2001 are strongly recommended to use 'cvs update' to obtain the current cvs code.
Bugzilla 2.14.1 is a security update; patches from a number of security-related bugs which have already been applied to the working source version 2.15 in cvs, have been applied to Bugzilla 2.14 to create the new stable release 2.14.1, which fixes several security issues discovered since version 2.14 was released, which we believe are too serious to wait for our upcoming 2.16 release.
There are many patches that need to be applied to properly close these holes, so they are not included here. If you will not be upgrading your system and instead wish to apply these patches to your existing system, a single patch which can be applied to a Bugzilla 2.14 installation is available at http://www.bugzilla.org/bugzilla2.14to2.14.1.patch
Complete bug reports for all bugs can be obtained by visiting the following URL: http://bugzilla.mozilla.org/show_bug.cgi?id=XXXXX where you replace the XXXXX at the end of the URL with a bug number as listed below. You may also enter the bug numbers in the "enter a bug#" box on the main page at http://bugzilla.mozilla.org/ or in the footer of any other page on bugzilla.mozilla.org.
*** SECURITY ISSUES RESOLVED ***
- Multiple instances of user-account hijacking capability were fixed (Bugs 54901, 108385, 185516)
- Two occurrences of allowing data protected by Bugzilla's groupset restrictions to be visible to users outside of those groups were fixes (Bugs 102141, 108821)
- One instance of an untrusted variable being echoed back to a user via HTML was fixed (Bug 98146)
- Multiple instances of untrusted variables being passed to SQL queries were fixed (Bugs 108812, 108822, 109679, 109690)
More detailed summaries of the specific exploits are available in the release notes, which are available on the project web site.
General information about the Bugzilla bug-tracking system can be found at http://www.bugzilla.org/
Comments and follow-ups can be directed to the
netscape.public.mozilla.webtools newsgroup or the mozilla-webtools mailing list (see http://www.mozilla.org/community.html for directions how to access these forums).
--
Dave Miller
Lead Software Engineer/System Administrator, Syndicomm Online
http://www.syndicomm.com/ bugdude1@syndicomm.com
Spotlight

Information security executives need to be strategic thinkers
Posted on 17 June 2013. | George Baker, the Director of Information Security at Exostar, talks about the challenges in working in a dynamic threat landscape, offers tips for aspiring infosec leaders, and more.

Large orgs in denial about own security breaches?
Posted on 14 June 2013. | Over two thirds (66%) of large organizations said they either had not experienced a security incident in the last 12-18 months or were unsure if they had.

Vulnerability scanning with PureCloud
Posted on 12 June 2013. | nCircle PureCloud is a cloud-based network security scanning product built upon the companies' vulnerability and risk management system IP360.

To hack back or not to hack back?
Posted on 12 June 2013. | If you think of cyberspace as a new resource for you and your organization, it makes sense to protect your part of it as best you can. But is it a good idea?

Reactions from the security community to the NSA spying scandal
Posted on 11 June 2013. | Read on for comments on this scandal that Help Net Security received from a variety of security professionals and analysts.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.







