Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian 3.0 DSA 153-2 Critical: Mantis Code Exec and Escalation Issues

debian
Calendar Grey August 20, 2002
Debian Logo
Enhancements focusing on multiple community weaknesses such as unauthorized access and code execution flaws in the Mantis application suite.
Multiple local vulnerabilities including cross site code execution and privilege escalation vulnerabilities have been fixed.

Summary

Jeroen Latour pointed out that we missed one uninitialized variable in
DSA 153-1, which was insecurely used with file inclusions in the
Mantis package, a php based bug tracking system. When such occasions
are exploited, a remote user is able to execute arbitrary code under
the webserver user id on the web server hosting the mantis system.

Jeroen Latour discovered that Mantis did not check all user input,
especially if they do not come directly from form fields. This opens
up a wide variety of SQL poisoning vulnerabilities on systems without
magic_quotes_gpc enabled. Most of these vulnerabilities are only
exploitable in a limited manner, since it is no longer possible to
execute multiple queries using one call to mysql_query(). There is
one query which can be tricked into changing an account's access
level.

Jeroen Latour also reported that it is possible to instruct Mantis to
show reporters only the bugs that they reported, by setting the
limit_reporters option to ON. However, when formatting t...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: mantis

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here