mkanat%bugzilla.org
e3a630c448
Bug 707170: Several features about custom fields are missing in the documentation
...
r=dkl a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@263146 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-08 23:03:26 +00:00
mkanat%bugzilla.org
ad537393f8
Bug 692354: Incorrect parameter type in WebServices documentation for Bug.add_comment
...
r/a=mkanat
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@263135 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-05 21:35:28 +00:00
mkanat%bugzilla.org
91adaa238f
Bug 591610: Custom field doc doesn't include 'Bug ID' type
...
r=timello a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@263128 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-02 16:50:47 +00:00
mkanat%bugzilla.org
cfe7c02887
Bug 531257: Wrong error codes in WebServices documentation
...
r=gerv a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@263076 18797224-902f-48f8-a5cc-f745e15eee43
2011-11-16 17:02:28 +00:00
mkanat%bugzilla.org
3d0d3db3f8
Bug 445804: Suggested crontab configuration opens security hole
...
r/a=mkanat
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262979 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-15 12:35:24 +00:00
mkanat%bugzilla.org
f6ee659898
Bump the version number post-release.
...
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262610 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-06 00:19:39 +00:00
mkanat%bugzilla.org
03e390ba79
Bump version number for 3.4.12.
...
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262595 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-05 00:19:47 +00:00
mkanat%bugzilla.org
e2c29f672f
Bug 670868: (CVE-2011-2978) [SECURITY] Account preferences page trusts user-modifiable field for obtaining current e-mail address
...
r/a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262586 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 21:06:12 +00:00
mkanat%bugzilla.org
586f6e4005
Bug 637981: (CVE-2011-2379) [SECURITY] "Raw Unified" patch diffs can cause XSS on this domain in IE 6-8 and Safari
...
r/a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262585 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 20:49:57 +00:00
mkanat%bugzilla.org
9fd9b6d61e
Bug 653477: (CVE-2011-2380) [SECURITY] Group names can be guessed when creating or editing a bug
...
r=dkl a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262583 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 20:20:54 +00:00
mkanat%bugzilla.org
e015d44c5f
Bug 660053: (CVE-2011-2976) [SECURITY] If a BUGLIST cookie is compromised, it can be used to XSS show_bug.cgi and inject HTML into <head>
...
r/a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262582 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 20:19:52 +00:00
mkanat%bugzilla.org
20d6cb1cf0
Bug 657158 - (CVE-2011-2381) [SECURITY] Request email headers for attachment containing newline are corrupt
...
[r=glob a=LpSolit]
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262580 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 19:34:39 +00:00
mkanat%bugzilla.org
5066483f79
Bug 675751: Release notes for Bugzilla 3.4.12
...
r/a=mkanat
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262565 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-02 23:02:23 +00:00
mkanat%bugzilla.org
dbebeb1bc8
Bump the version number post-release.
...
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262263 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-28 04:06:09 +00:00
mkanat%bugzilla.org
e5c3c70072
Bump version number for 3.4.11.
...
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262261 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-28 02:21:17 +00:00
mkanat%bugzilla.org
0e524fd9e4
Bug 653275 - Release Notes for Bugzilla 3.4.11
...
r=LpSolit, a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262252 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-28 00:31:15 +00:00
mkanat%bugzilla.org
a472cb9c13
Bug 646578: Remove the usage of Math::Random::Secure, as it is too difficult
...
to install on older branches.
r=LpSolit, a=mkanat
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262245 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-27 22:23:58 +00:00
mkanat%bugzilla.org
67e7269a7e
Bug 311392 - Typos and proper name of Red Hat's stuff
...
author=Matt Selksy <selsky_at_columbia_dot_edu>, r=dkl, a=mkanat
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262089 18797224-902f-48f8-a5cc-f745e15eee43
2011-03-22 20:21:02 +00:00
mkanat%bugzilla.org
4b149ccfe6
Bug 586011 - Change references to 'DarwinPorts' to 'MacPorts' (proper project name)
...
author=Matt Selsky <selsky_at_columbia_dot_edu>, r=dkl,a=mkanat
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@262069 18797224-902f-48f8-a5cc-f745e15eee43
2011-03-18 21:04:46 +00:00
mkanat%bugzilla.org
4ae7b7c0ba
Bug 633422: Fix the documentation for User.get's include_disabled parameter
...
and make User.get check that its required parameters are passed.
r=LpSolit, a=mkanat
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261932 18797224-902f-48f8-a5cc-f745e15eee43
2011-02-14 07:51:04 +00:00
mkanat%bugzilla.org
f1b34e034a
Bump the version number post-release.
...
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261828 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-25 02:06:03 +00:00
mkanat%bugzilla.org
adc20b1ef9
Bump version number for 3.4.10.
...
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261822 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 23:46:37 +00:00
mkanat%bugzilla.org
e5077c84dc
Bug 619594: (CVE-2010-4568) [SECURITY] Improve the randomness of
...
generate_random_password, to protect against an account compromise issue
and other critical vulnerabilities.
r=LpSolit, a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261817 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 22:07:59 +00:00
mkanat%bugzilla.org
eac55efd57
Bug 621105 - [SECURITY] Voting lacks CSRF protection
...
r=mkanat,a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261814 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 19:53:26 +00:00
mkanat%bugzilla.org
4de3357f3e
Bug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking for javascript: or data: URLs in the URL field can be evaded with prefixed whitespace
...
and
Bug 628034: (CVE-2011-0048) [SECURITY] For not-logged-in users, the URL field doesn't safeguard against javascript: or data: URLs
r=dkl a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261813 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 18:53:58 +00:00
mkanat%bugzilla.org
fc80d02e68
Bug 621572: (CVE-2010-4572) [SECURITY] chart.cgi vulnerable to header-injection due to use of |print "Location:"| instead of $cgi->redirect
...
[r=mkanat a=LpSolit]
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261812 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 18:31:15 +00:00
mkanat%bugzilla.org
90dc5479bd
Bug 621110: [SECURITY] Quips (adding/approving/deleting) lacks CSRF protection
...
r=dkl a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261806 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 17:38:25 +00:00
mkanat%bugzilla.org
1830d31c57
Bug 621108: [SECURITY] Creating/editing charts lacks CSRF protection
...
r=dkl a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261805 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 17:27:06 +00:00
mkanat%bugzilla.org
08b58e9c0f
Bug 627930 - Release Notes for Bugzilla 3.4.10
...
r=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261800 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-24 04:24:47 +00:00
mkanat%bugzilla.org
b661633eaf
Bug 591165: (CVE-2010-4411) [SECURITY] Bump minimum required version of CGI.pm to v3.51 in order to address header injection vulnerability.
...
[r=mkanat a=mkanat]
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261784 18797224-902f-48f8-a5cc-f745e15eee43
2011-01-21 21:22:55 +00:00
mkanat%bugzilla.org
80cdf1adb3
Bug 416784: In PostgreSQL 8.1 and newer, createuser takes the argument -R instead of -A
...
r=manu a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261600 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-27 21:22:33 +00:00
mkanat%bugzilla.org
5c0030e99d
Bug 591165: (CVE-2010-2761) [SECURITY] Add CGI.pm v3.50 as an optional module in order to address header injection vulnerability.
...
[r=mkanat a=mkanat]
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261559 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-11 02:48:24 +00:00
mkanat%bugzilla.org
a1a8fefcab
Bump the version number post-release.
...
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261518 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-03 01:50:41 +00:00
mkanat%bugzilla.org
b23382bf2e
Bump version number for 3.4.9.
...
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261513 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-03 00:47:33 +00:00
mkanat%bugzilla.org
b7103a6949
Bug 600464: (CVE-2010-3172) [SECURITY] Content/Header injection due to non-random multipart/x-mixed-replace boundary
...
r=mkanat a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261506 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-02 23:37:45 +00:00
mkanat%bugzilla.org
7720afc3db
Bug 419014: (CVE-2010-3764) [SECURITY] Old charts are not project specific, and product names are viewable in graphs/
...
r=wurblzap a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261505 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-02 23:23:21 +00:00
mkanat%bugzilla.org
400ec487ed
Bug 608645: Release Notes for Bugzilla 3.4.9
...
r=LpSolit, a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261501 18797224-902f-48f8-a5cc-f745e15eee43
2010-11-01 07:01:45 +00:00
mkanat%bugzilla.org
b976c34c40
Bug 589547: Wrong description for editing a flag
...
r/a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261256 18797224-902f-48f8-a5cc-f745e15eee43
2010-09-19 00:26:45 +00:00
mkanat%bugzilla.org
0819bd31ad
Bug 589525: fix typo
...
r/a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@261255 18797224-902f-48f8-a5cc-f745e15eee43
2010-09-19 00:25:20 +00:00
mkanat%bugzilla.org
c42f6322cd
Bump version number post-release.
...
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@260993 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-06 02:35:39 +00:00
mkanat%bugzilla.org
138d0241c1
Bump the version number for 3.4.8.
...
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@260988 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-06 01:19:20 +00:00
mkanat%bugzilla.org
ae9a482e4b
Bug 583690: (CVE-2010-2759) [SECURITY][PostgreSQL] Bugzilla crashes when viewing a bug if a comment contains 'bug <num>' or 'attachment <num>' where <num> is greater than the max allowed integer
...
r=mkanat a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@260976 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-04 22:22:01 +00:00
mkanat%bugzilla.org
078e81acf3
Bug 577139: (CVE-2010-2758) [SECURITY] request.cgi and duplicates.cgi let you know whether a product exists or not
...
r=mkanat a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@260975 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-04 22:04:01 +00:00
mkanat%bugzilla.org
f27a3d6ecc
Bug 450013: (CVE-2010-2757) [SECURITY] Can sudo a user without sending email
...
r=glob a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@260974 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-04 21:52:54 +00:00
mkanat%bugzilla.org
c0e5d50d39
Bug 417048: (CVE-2010-2756) [SECURITY] Boolean charts let me query for users being in any given group
...
r=mkanat a=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@260972 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-04 21:35:40 +00:00
mkanat%bugzilla.org
567378682d
Bug 584428: Release Notes for Bugzilla 3.4.8
...
r=LpSolit
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@260970 18797224-902f-48f8-a5cc-f745e15eee43
2010-08-04 18:20:53 +00:00
mkanat%bugzilla.org
d1b626d75f
Bug 455585: Installation docs should recommend using package management instead of CPAN
...
r=glob
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@260783 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-15 11:24:26 +00:00
mkanat%bugzilla.org
4a5f79d8f7
Bug 193193: Better explain what the checkboxes in Edit Users-Group Access/Privileges are for
...
r=glob
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@260782 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-15 11:07:36 +00:00
mkanat%bugzilla.org
c7184b3125
Bug 472452: Rephrase documentation about deleting custom fields
...
r=glob
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@260781 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-15 10:50:49 +00:00
mkanat%bugzilla.org
af5a259e14
Bug 536183: Docs claim bug lifecycle is "hard-coded" despite that's no longer true
...
r=gerv a=mkanat
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_4-BRANCH@260757 18797224-902f-48f8-a5cc-f745e15eee43
2010-07-13 23:27:04 +00:00