Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Debian DSA-3120-1 Moderate: Mantis SQL Injection And Phishing Risk

debian
Calendar Grey January 6, 2015
Scroller Debian
Various vulnerabilities detected in Mantis may pose risks for phishing attempts and SQL injection attacks; it is recommended to upgrade Debian installations.
Multiple security issues have been found in the Mantis bug tracking system, which may result in phishing, information disclosure, CAPTCHA bypass, SQL injection, cross-site scriptin...

Summary

Multiple security issues have been found in the Mantis bug tracking
system, which may result in phishing, information disclosure, CAPTCHA
bypass, SQL injection, cross-site scripting or the execution of arbitrary
PHP code.

For the stable distribution (wheezy), these problems have been fixed in
version 1.2.18-1.

We recommend that you upgrade your mantis packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: mantis
CVE ID: CVE-2014-6316 CVE-2014-7146 CVE-2014-8553 CVE-2014-8554

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.