CVE-2011-0048

NameCVE-2011-0048
DescriptionBugzilla before 3.2.10, 3.4.x before 3.4.10, 3.6.x before 3.6.4, and 4.0.x before 4.0rc2 creates a clickable link for a (1) javascript: or (2) data: URI in the URL (aka bug_file_loc) field, which allows remote attackers to conduct cross-site scripting (XSS) attacks against logged-out users via a crafted URI.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2322-1
NVD severitymedium (attack range: remote)
Debian Bugs611176

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bugzillasource(unstable)(unfixed)medium611176
bugzillasourcesqueeze3.6.2.0-4.4medium

Notes

http://www.bugzilla.org/security/3.2.9/

Search for package or bug name: Reporting problems