[prev in list] [next in list] [prev in thread] [next in thread]
List: oss-security
Subject: Re: [oss-security] CVE request: MantisBT <=1.2.3 (db_type)
From: Josh Bressers <bressers () redhat ! com>
Date: 2010-12-16 13:58:34
Message-ID: 1402961491.1582851292507914388.JavaMail.root () zmail01 ! collab ! prod ! int ! phx2 ! redhat ! com
[Download RAW message or body]
Please use CVE-2010-4348 for the XSS.
CVE-2010-4349 for the path disclosure.
Thanks.
--
JB
----- "David Hicks" <hickseydr@optusnet.com.au> wrote:
> This is a CVE request for a vulnerability discovered in MantisBT
> <1.2.4
> by Gjoko Krstic of Zero Science Lab as per the following advisory:
>
> http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4983.php
>
> MantisBT 1.2.4 has been released to resolve this issue.
>
> For distributions or users using MantisBT 1.1.x, the following patch
> can
> be applied:
> http://git.mantisbt.org/?p=mantisbt.git;a=commitdiff_plain;h=2641fdc60d2032ae1586338d6416e1eadabd7590
>
> Please note that MantisBT 1.1.x is not recommended for use due to
> many
> security improvements and features implemented in MantisBT 1.2.x (but
> not backported to 1.1.x).
>
> Detailed information about this vulnerability can be found in this
> bug
> report: http://www.mantisbt.org/bugs/view.php?id=12607
>
> Regards,
>
> David Hicks
> MantisBT Developer
> mantisbt.org, #mantishelp freenode
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic