Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora: 2015-12012 Critical: Mantis Security Vulnerability Fix Released

fedora
Calendar Grey August 7, 2015
Dist Fedora Esm H88
Important security patch for Mantis on Fedora 22 tackling the information exposure flaw CVE-2015-5059.
Security fix for CVE-2015-5059

Summary

Mantis is a free popular web-based issue tracking system.

It is written in the PHP scripting language and works with MySQL, MS SQL,

and PostgreSQL databases and a web server.

Almost any web browser should be able to function as a client.

Documentation can be found in: /usr/share/doc/mantis

When the package has finished installing, you will need to perform some

additional configuration steps; these are described in:

/usr/share/doc/mantis/README.Fedora

Update Information:

Security fix for CVE-2015-5059

Change Log

* Thu Jul 23 2015 Gianluca Sforna - 1.2.19-3 - apply upstream patch for CVE-2015-5059 (#1237199) * Wed Jun 17 2015 Fedora Release Engineering - 1.2.19-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild

References


[ 1 ] Bug #1237199 - CVE-2015-5059 mantis: information disclosure due to too wide $g_view_proj_doc_threshold permission https://bugzilla.redhat.com/show_bug.cgi?id=1237199

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update mantis' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: mantis
Product: Fedora 22
Version: 1.2.19
Release: 3.fc22
Summary: Web-based issue tracking system

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here