<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Wazi &#187; bugzilla</title>
	<atom:link href="http://olex.openlogic.com/wazi/tag/bugzilla/feed/" rel="self" type="application/rss+xml" />
	<link>http://olex.openlogic.com/wazi</link>
	<description>Thinking OPEN</description>
	<lastBuildDate>Fri, 19 Mar 2010 03:29:34 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium/</guid>
		<description><![CDATA[Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances....

CVE Identifier: CVE-2009-3387
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla 3.3.1 through 3.4.4, 3.5.1, and 3.5.2 does not allow group restrictions to be preserved throughout the process of moving a bug to a different product category, which allows remote attackers to obtain sensitive information via a request for a bug in opportunistic circumstances.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3387" target="_blank">CVE-2009-3387</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-2/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-2/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-2/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-3/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-3/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-3/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-4/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-4/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-4/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-5/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-5/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-5/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-6/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-6/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-6/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-7/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-7/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-7/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-8/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-8/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-8/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-9/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-9/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-9/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-10/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-10/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-10/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-10/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-11/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-11/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-11/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-12/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-12/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-12/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-12/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-13/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-13/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-13/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-13/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-14/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-14/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-14/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-14/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-15/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-15/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-15/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-15/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-16/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-16/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-16/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-16/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-17/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-17/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-17/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-17/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-18/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-18/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-18/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-18/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-19/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-19/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-19/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-19/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bugzilla 3.5.2 and prior [Medium]</title>
		<link>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-20/</link>
		<comments>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-20/#comments</comments>
		<pubDate>Wed, 03 Feb 2010 21:30:00 +0000</pubDate>
		<dc:creator>Security Team</dc:creator>
				<category><![CDATA[Security Notifications]]></category>
		<category><![CDATA[bugzilla]]></category>

		<guid isPermaLink="false">http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-20/</guid>
		<description><![CDATA[Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt....

CVE Identifier: CVE-2009-3989
Vulnerability Type(s): 
Severity: Medium
]]></description>
			<content:encoded><![CDATA[<h3>Affects:</h3>
<ul>
<li>Bugzilla 3.5.2 and prior [Medium]
</ul>
<h3>Description</h3>
<p>Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.</p>
<p>If you have questions about this security warning or need to have it translated and you have an active technical support contract, please call 1-888-OPENLOGIC or email us at support@openlogic.com.</p>
<p>
CVE Identifier: <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3989" target="_blank">CVE-2009-3989</a><br />
Severity: Medium
</p>
<div id="attachment_2101" class="wp-caption alignright" style="width: 193px"><a href="http://nvd.nist.gov/download.cfm"><img class="size-medium wp-image-2101" title="NVD Logo" src="http://olex.openlogic.com/wazi/wp-content/uploads/2009/01/nvd.png" alt="National Vulnerabilities Database" width="183" height="87" /></a><p class="wp-caption-text">NIST National Vulnerabilities Database</p></div>
]]></content:encoded>
			<wfw:commentRss>http://olex.openlogic.com/wazi/2010/bugzilla-3-5-2-and-prior-medium-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
