Release date:
Updated on:
Affected Systems:
Mozilla Bugzilla 4.x
Mozilla Bugzilla 3.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56504
Cve id: CVE-2012-4199
Bugzilla is an open-source defect tracking system that manages the entire lifecycle of defects in software development, such as submitting, repairing, and disabling defects.
If the Custom Field of Bugzilla is controlled by products or invisible components, the JS Code generated by this custom field will leak its name.
<* Source: Frederic Buclin
Link: https://bugzilla.mozilla.org/show_bug.cgi? Id = 731178
Http://www.bugzilla.org/security/3.6.11/
Http://secunia.com/advisories/51265/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Mozilla
-------
The vendor has released patch 3.6.12, 4.0.9, 4.2.4, and 4.4rc1 to fix this security problem. Please download the patch from the vendor's homepage:
Http://www.mozilla.org/security/