213812 Commits

Author SHA1 Message Date
mkanat%bugzilla.org
ffc9206b9e Bumped version post release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@264081 18797224-902f-48f8-a5cc-f745e15eee43
2012-07-26 23:01:15 +00:00
mkanat%bugzilla.org
e86a5d6b73 Bump version to 3.6.10
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@264074 18797224-902f-48f8-a5cc-f745e15eee43
2012-07-26 21:30:39 +00:00
mkanat%bugzilla.org
6d13074b6a Bug 777586: (CVE-2012-1969) [SECURITY] The description of private attachments is still visible to unauthorized users when mentioned in a comment
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@264073 18797224-902f-48f8-a5cc-f745e15eee43
2012-07-26 21:16:55 +00:00
mkanat%bugzilla.org
f918cd5c73 Bug 777676: Release notes for Bugzilla 3.6.10
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@264068 18797224-902f-48f8-a5cc-f745e15eee43
2012-07-26 14:01:21 +00:00
mkanat%bugzilla.org
309bf3cd85 Bug 776103 - Syntax error in Bugzilla::User::Setting API doc
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@264065 18797224-902f-48f8-a5cc-f745e15eee43
2012-07-25 21:46:57 +00:00
mkanat%bugzilla.org
c0ffaa3dc3 Bumping the version post-release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263718 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 22:33:02 +00:00
mkanat%bugzilla.org
5862edbca2 Bump version to 3.6.9
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263715 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 18:02:59 +00:00
mkanat%bugzilla.org
bd106f6bf9 Bug 745397: (CVE-2012-0466) [SECURITY] The JS template for buglists permits attackers to access all bugs that the victim can see
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263712 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 17:08:02 +00:00
mkanat%bugzilla.org
c1c0a4c1cb Bug 728639: (CVE-2012-0465) [SECURITY] User lockout policy can be bypassed by altering the X-FORWARDED-FOR header
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263711 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 17:06:52 +00:00
mkanat%bugzilla.org
9b29417520 Bug 746547: SMALLSERIAL is of type INT2, not INT1
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263709 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-18 15:04:18 +00:00
mkanat%bugzilla.org
283a9ced72 Bug 727892: Update relnotes for 3.6.9
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263700 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-17 19:16:48 +00:00
mkanat%bugzilla.org
fdbd0197c5 Bug 727892: Release notes for Bugzilla 3.6.9
r=dkl


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263677 18797224-902f-48f8-a5cc-f745e15eee43
2012-04-12 19:17:06 +00:00
mkanat%bugzilla.org
a7ed6110b3 Bug 731725 - In the documentation license, the address of the FSF is incorrect
r=dkl, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263512 18797224-902f-48f8-a5cc-f745e15eee43
2012-03-01 23:05:25 +00:00
mkanat%bugzilla.org
a9617cdf14 Test 1 fails if PERLLIB contains paths with whitespace.
r=gerv; a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263412 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-15 18:04:20 +00:00
mkanat%bugzilla.org
674f412e5a Bug 727240: The POD for Bug.attachments is wrong about the format of the returned data
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263407 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-14 22:24:30 +00:00
mkanat%bugzilla.org
c96e22999f Bump the version number post-release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263354 18797224-902f-48f8-a5cc-f745e15eee43
2012-02-01 00:04:54 +00:00
mkanat%bugzilla.org
d02663492b Bumped to version 3.6.8
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263349 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-31 17:01:35 +00:00
mkanat%bugzilla.org
cb38f60950 Bug 718319: (CVE-2012-0440) [SECURITY] JSON-RPC permits to bypass token checks and can lead to CSRF (no victim's action required)
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263342 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-31 16:19:08 +00:00
mkanat%bugzilla.org
4ca780e6c7 Bug 714472: (CVE-2012-0448) [SECURITY] utf8 homoglyphs are allowed in email addresses, which could allow an attacker to be CC'ed to private bugs by accident
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263340 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-31 16:08:48 +00:00
mkanat%bugzilla.org
98a4ae3979 Bug 720751 - Release notes for Bugzilla 3.6.8
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263323 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-27 22:17:57 +00:00
mkanat%bugzilla.org
e48e8dc48c Bug 469068: SMTP parameters not documented
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263293 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-21 11:20:52 +00:00
mkanat%bugzilla.org
9231605347 Bug 591638: In the admin page, the link to edit field values is named 'Field Values', not 'Legal Values'
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263253 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-11 12:35:15 +00:00
mkanat%bugzilla.org
a6af76517d Bug 319684: The documentation is unclear about how to disable quips
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263237 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-06 10:06:02 +00:00
mkanat%bugzilla.org
a92a44053c Bug 706753: Bugzilla will not work with newest version of JSON::RPC 1.01 due to non-backward compatibility
r=dkl r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263226 18797224-902f-48f8-a5cc-f745e15eee43
2012-01-05 01:02:37 +00:00
mkanat%bugzilla.org
d4f4860b94 Bump the version number post-release
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263216 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-29 18:03:54 +00:00
mkanat%bugzilla.org
7479c3d169 Bump version for 3.6.7
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263209 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-28 23:17:36 +00:00
mkanat%bugzilla.org
756f0c559e Bug 711714: (CVE-2011-3667) [SECURITY] The User.offer_account_by_email WebService method lets you create new user accounts independently of the value of Bugzilla::Auth::Verify::*::user_can_create_account
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263205 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-28 22:21:31 +00:00
mkanat%bugzilla.org
54bf1614e5 Bug 697699 - (CVE-2011-3657) [SECURITY] XSS when viewing new charts or tabular and graphical reports in debug mode
r=gerv, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263202 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-28 22:03:37 +00:00
mkanat%bugzilla.org
823b470fa1 Bug 713344: Release notes for Bugzilla 3.6.7
r=wicked a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263194 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-26 10:47:51 +00:00
mkanat%bugzilla.org
ad1ad97564 Bug 707170: Several features about custom fields are missing in the documentation
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263146 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-08 23:03:26 +00:00
mkanat%bugzilla.org
34eb69f55e Bug 692354: Incorrect parameter type in WebServices documentation for Bug.add_comment
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263135 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-05 21:35:28 +00:00
mkanat%bugzilla.org
9a9e9ee3cf Bug 707594: Fix broken account lockout notifications
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263130 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-05 16:48:52 +00:00
mkanat%bugzilla.org
a158c71df8 Bug 591610: Custom field doc doesn't include 'Bug ID' type
r=timello a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263128 18797224-902f-48f8-a5cc-f745e15eee43
2011-12-02 16:50:47 +00:00
mkanat%bugzilla.org
4d19b12121 Bug 531257: Wrong error codes in WebServices documentation
r=gerv a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@263076 18797224-902f-48f8-a5cc-f745e15eee43
2011-11-16 17:02:28 +00:00
mkanat%bugzilla.org
16f2744e63 Bug 691243: Fix typo
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262987 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-15 13:35:13 +00:00
mkanat%bugzilla.org
018c63a1c8 Bug 620694: MySQL is not 'required' RDBMS for Bugzilla
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262981 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-15 12:50:10 +00:00
mkanat%bugzilla.org
d8c3ead78b Bug 445804: Suggested crontab configuration opens security hole
r/a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262979 18797224-902f-48f8-a5cc-f745e15eee43
2011-10-15 12:35:24 +00:00
mkanat%bugzilla.org
e0f7f71b31 Bump the version number post-release.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262610 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-06 00:19:39 +00:00
mkanat%bugzilla.org
997061796a Bump version number for 3.6.6.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262593 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-05 00:18:47 +00:00
mkanat%bugzilla.org
432a88165a Bug 670868: (CVE-2011-2978) [SECURITY] Account preferences page trusts user-modifiable field for obtaining current e-mail address
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262586 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 21:06:12 +00:00
mkanat%bugzilla.org
9ed06e7b6e Bug 637981: (CVE-2011-2379) [SECURITY] "Raw Unified" patch diffs can cause XSS on this domain in IE 6-8 and Safari
r/a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262585 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 20:49:57 +00:00
mkanat%bugzilla.org
79ac518c92 Bug 660502: (CVE-2011-2977) [SECURITY] Temporary files for uploaded attachments are not deleted on Windows
r=glob a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262584 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 20:33:34 +00:00
mkanat%bugzilla.org
a4c8ab1653 Bug 653477: (CVE-2011-2380) [SECURITY] Group names can be guessed when creating or editing a bug
r=dkl a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262583 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 20:20:54 +00:00
mkanat%bugzilla.org
91d4f8b7b2 Bug 657158 - (CVE-2011-2381) [SECURITY] Request email headers for attachment containing newline are corrupt
[r=glob a=LpSolit]


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262580 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-04 19:34:39 +00:00
mkanat%bugzilla.org
7a38fe66c0 Bug 675752: Release notes for Bugzilla 3.6.6
r=mkanat a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262564 18797224-902f-48f8-a5cc-f745e15eee43
2011-08-02 23:01:21 +00:00
mkanat%bugzilla.org
3b0e00fd3c Bug 653406: fix escaping of url vars in error messages
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262270 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-29 05:49:35 +00:00
mkanat%bugzilla.org
b77fa6e570 Bump the version number post-release.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262263 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-28 04:06:09 +00:00
mkanat%bugzilla.org
19fdf4332b Bump version number for 3.6.5.
git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262259 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-28 02:20:06 +00:00
mkanat%bugzilla.org
4fca133da2 Bug 653274 - Release Notes for Bugzilla 3.6.5
r=LpSolit, a=LpSolit


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262251 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-28 00:29:58 +00:00
mkanat%bugzilla.org
e4f4fed7d3 Bug 646578: Make Math::Random::Secure fail to install if its dependencies
don't install properly, when using install-module.pl.
r=glob, a=mkanat


git-svn-id: svn://10.0.0.236/branches/BUGZILLA-3_6-BRANCH@262244 18797224-902f-48f8-a5cc-f745e15eee43
2011-04-27 22:22:46 +00:00