Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Bump version number for 3.4.11.release-3.4.11bugzilla-3.4.11 | Max Kanat-Alexander | 2011-04-27 | 2 | -3/+3 |
| | | | https://bugzilla.mozilla.org/show_bug.cgi?id=652474 | ||||
* | Bug 653275 - Release Notes for Bugzilla 3.4.11 | Max Kanat-Alexander | 2011-04-27 | 1 | -0/+11 |
| | | | | r=LpSolit, a=LpSolit | ||||
* | Bug 646578: Remove the usage of Math::Random::Secure, as it is too difficult | Max Kanat-Alexander | 2011-04-27 | 3 | -34/+11 |
| | | | | | to install on older branches. r=LpSolit, a=mkanat | ||||
* | Bug 311392 - Typos and proper name of Red Hat's stuff | Matt Selsky | 2011-03-22 | 2 | -10/+10 |
| | | | | author=Matt Selksy <selsky_at_columbia_dot_edu>, r=dkl, a=mkanat | ||||
* | Bug 586011 - Change references to 'DarwinPorts' to 'MacPorts' (proper ↵ | David Lawrence | 2011-03-18 | 1 | -3/+3 |
| | | | | | | project name) author=Matt Selsky <selsky_at_columbia_dot_edu>, r=dkl,a=mkanat | ||||
* | Bug 633422: Fix the documentation for User.get's include_disabled parameter | Max Kanat-Alexander | 2011-02-13 | 1 | -0/+5 |
| | | | | | and make User.get check that its required parameters are passed. r=LpSolit, a=mkanat | ||||
* | Bump the version number post-release. | Max Kanat-Alexander | 2011-01-24 | 1 | -1/+1 |
| | |||||
* | Bump version number for 3.4.10.release-3.4.10bugzilla-3.4.10 | Max Kanat-Alexander | 2011-01-24 | 2 | -4/+4 |
| | |||||
* | Bug 619594: (CVE-2010-4568) [SECURITY] Improve the randomness of | Max Kanat-Alexander | 2011-01-24 | 4 | -5/+76 |
| | | | | | | | generate_random_password, to protect against an account compromise issue and other critical vulnerabilities. r=LpSolit, a=LpSolit https://bugzilla.mozilla.org/show_bug.cgi?id=621591 | ||||
* | Bug 621105 - [SECURITY] Voting lacks CSRF protection | David Lawrence | 2011-01-24 | 3 | -0/+6 |
| | | | | r=mkanat,a=LpSolit | ||||
* | Bug 619588: (CVE-2010-4567) [SECURITY] Safety checks that disallow clicking ↵ | Frédéric Buclin | 2011-01-24 | 3 | -8/+20 |
| | | | | | | | | | | for javascript: or data: URLs in the URL field can be evaded with prefixed whitespace and Bug 628034: (CVE-2011-0048) [SECURITY] For not-logged-in users, the URL field doesn't safeguard against javascript: or data: URLs r=dkl a=LpSolit | ||||
* | Bug 621572: (CVE-2010-4572) [SECURITY] chart.cgi vulnerable to ↵ | Reed Loden | 2011-01-24 | 1 | -3/+3 |
| | | | | | | header-injection due to use of |print "Location:"| instead of $cgi->redirect [r=mkanat a=LpSolit] | ||||
* | Bug 621110: [SECURITY] Quips (adding/approving/deleting) lacks CSRF protection | Frédéric Buclin | 2011-01-24 | 2 | -2/+12 |
| | | | | r=dkl a=LpSolit | ||||
* | Bug 621108: [SECURITY] Creating/editing charts lacks CSRF protection | Frédéric Buclin | 2011-01-24 | 3 | -3/+13 |
| | | | | r=dkl a=LpSolit | ||||
* | Bug 627930 - Release Notes for Bugzilla 3.4.10 | Max Kanat-Alexander | 2011-01-23 | 1 | -2/+10 |
| | | | | r=LpSolit | ||||
* | Bug 591165: (CVE-2010-4411) [SECURITY] Bump minimum required version of ↵ | Reed Loden | 2011-01-21 | 1 | -2/+2 |
| | | | | | | CGI.pm to v3.51 in order to address header injection vulnerability. [r=mkanat a=mkanat] | ||||
* | Bug 416784: In PostgreSQL 8.1 and newer, createuser takes the argument -R ↵ | Frédéric Buclin | 2010-11-27 | 1 | -3/+7 |
| | | | | | | instead of -A r=manu a=LpSolit | ||||
* | Bug 591165: (CVE-2010-2761) [SECURITY] Add CGI.pm v3.50 as an optional ↵ | Reed Loden | 2010-11-10 | 1 | -0/+9 |
| | | | | | | module in order to address header injection vulnerability. [r=mkanat a=mkanat] | ||||
* | Bump the version number post-release. | Max Kanat-Alexander | 2010-11-02 | 1 | -1/+1 |
| | |||||
* | Bump version number for 3.4.9.release-3.4.9bugzilla-3.4.9 | Max Kanat-Alexander | 2010-11-02 | 2 | -3/+3 |
| | | | https://bugzilla.mozilla.org/show_bug.cgi?id=604255 | ||||
* | Bug 600464: (CVE-2010-3172) [SECURITY] Content/Header injection due to ↵ | Byron Jones | 2010-11-03 | 1 | -1/+2 |
| | | | | | | non-random multipart/x-mixed-replace boundary r=mkanat a=LpSolit | ||||
* | Bug 419014: (CVE-2010-3764) [SECURITY] Old charts are not project specific, ↵ | Frédéric Buclin | 2010-11-03 | 6 | -79/+73 |
| | | | | | | and product names are viewable in graphs/ r=wurblzap a=LpSolit | ||||
* | Bug 608645: Release Notes for Bugzilla 3.4.9 | Max Kanat-Alexander | 2010-10-31 | 1 | -0/+6 |
| | | | | r=LpSolit, a=LpSolit | ||||
* | Bug 589547: Wrong description for editing a flag | A. Shimono (himorin) | 2010-09-19 | 1 | -2/+2 |
| | | | | r/a=LpSolit | ||||
* | Bug 589525: fix typo | A. Shimono (himorin) | 2010-09-19 | 1 | -2/+1 |
| | | | | r/a=LpSolit | ||||
* | Bump version number post-release. | Max Kanat-Alexander | 2010-08-05 | 1 | -1/+1 |
| | |||||
* | Bump the version number for 3.4.8.release-3.4.8bugzilla-3.4.8 | Max Kanat-Alexander | 2010-08-05 | 2 | -3/+3 |
| | | | https://bugzilla.mozilla.org/show_bug.cgi?id=580206 | ||||
* | Bug 583690: (CVE-2010-2759) [SECURITY][PostgreSQL] Bugzilla crashes when ↵ | Frédéric Buclin | 2010-08-05 | 3 | -2/+10 |
| | | | | | | viewing a bug if a comment contains 'bug <num>' or 'attachment <num>' where <num> is greater than the max allowed integer r=mkanat a=LpSolit | ||||
* | Bug 577139: (CVE-2010-2758) [SECURITY] request.cgi and duplicates.cgi let ↵ | Frédéric Buclin | 2010-08-04 | 3 | -10/+23 |
| | | | | | | you know whether a product exists or not r=mkanat a=LpSolit | ||||
* | Bug 450013: (CVE-2010-2757) [SECURITY] Can sudo a user without sending email | Frédéric Buclin | 2010-08-04 | 4 | -19/+57 |
| | | | | r=glob a=LpSolit | ||||
* | Bug 417048: (CVE-2010-2756) [SECURITY] Boolean charts let me query for users ↵ | Frédéric Buclin | 2010-08-04 | 1 | -2/+4 |
| | | | | | | being in any given group r=mkanat a=LpSolit | ||||
* | Bug 584428: Release Notes for Bugzilla 3.4.8 | Max Kanat-Alexander | 2010-08-04 | 1 | -0/+10 |
| | | | | r=LpSolit | ||||
* | Bug 455585: Installation docs should recommend using package management ↵ | Frédéric Buclin | 2010-07-15 | 1 | -5/+10 |
| | | | | | | instead of CPAN r=glob | ||||
* | Bug 193193: Better explain what the checkboxes in Edit Users-Group ↵ | Frédéric Buclin | 2010-07-15 | 1 | -1/+4 |
| | | | | | | Access/Privileges are for r=glob | ||||
* | Bug 472452: Rephrase documentation about deleting custom fields | Frédéric Buclin | 2010-07-15 | 1 | -4/+7 |
| | | | | r=glob | ||||
* | Bug 536183: Docs claim bug lifecycle is "hard-coded" despite that's no ↵ | Frédéric Buclin | 2010-07-14 | 1 | -4/+6 |
| | | | | | | longer true r=gerv a=mkanat | ||||
* | Bug 577851: config.cgi crashes in 3.4.7, due to Bugzilla::Product::preload ↵ | Frédéric Buclin | 2010-07-14 | 1 | -3/+0 |
| | | | | | | (backout of bug 553255) r/a=mkanat | ||||
* | Bug 236651: Remove obsolete instructions from the "2.1.5 Perl Modules" section | Frédéric Buclin | 2010-07-13 | 1 | -124/+10 |
| | | | | r=reed | ||||
* | Bump version number post-release | Max Kanat-Alexander | 2010-06-24 | 1 | -1/+1 |
| | |||||
* | Bump the version number for 3.4.7.release-3.4.7bugzilla-3.4.7 | Max Kanat-Alexander | 2010-06-24 | 2 | -3/+3 |
| | | | https://bugzilla.mozilla.org/show_bug.cgi?id=559988 | ||||
* | Bug 309952: (CVE-2010-1204) [SECURITY] Protect boolean chart searches for | Max Kanat-Alexander | 2010-06-24 | 1 | -0/+8 |
| | | | | | | time-tracking fields from being used by users who are not in the timetrackinggroup. r=LpSolit, a=mkanat | ||||
* | Bug 566198: Release Notes for Bugzilla 3.4.7 | Max Kanat-Alexander | 2010-06-21 | 1 | -0/+34 |
| | | | | r=LpSolit, a=mkanat | ||||
* | Bug 284650: Beginning a chart name with an "_" (underscore) causes errors | Frédéric Buclin | 2010-04-08 | 1 | -0/+3 |
| | | | | r=mkanat a=LpSolit | ||||
* | Bug 557686: PostgreSQL crashes when deleting a custom field of type Date/Time | Frédéric Buclin | 2010-04-07 | 1 | -5/+1 |
| | | | | r=mkanat a=LpSolit | ||||
* | Bug 557495: PostgreSQL crashes when deleting a custom field of type BugID | Frédéric Buclin | 2010-04-07 | 1 | -2/+4 |
| | | | | r/a=mkanat | ||||
* | Bug 515515: For clients, mid-air collision results when user's timezone ↵ | Frank Becker | 2010-04-02 | 2 | -23/+75 |
| | | | | | | preference differs from server's r/a=mkanat | ||||
* | Bug 548327: Administration page should have hooks to extend the admin links | Tiago Mello | 2010-03-29 | 1 | -0/+4 |
| | | | | r/a=mkanat | ||||
* | Bug 548975: Under trunk Firefox builds with Direct2D enabled on Windows, | Guy Pyrzak | 2010-03-28 | 1 | -1/+1 |
| | | | | | <dt> tags were overly bold r=mkanat, a=mkanat | ||||
* | Bug 549814 - "Internal error when using login fields in header/footer after ↵ | Reed Loden | 2010-03-28 | 1 | -1/+1 |
| | | | | | | visiting token.cgi URL" [r=mkanat a=mkanat] | ||||
* | Bug 533927 - "email address domain filtering is applying to non-email fields ↵ | Reed Loden | 2010-03-27 | 1 | -40/+32 |
| | | | | | | in the history" [r=LpSolit a=LpSolit] |