Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Gentoo: 200812-07 High Severity: Mantis Remote Execution Risks

gentoo
Calendar Grey December 2, 2008
Dist Gentoo Esm H88
Numerous flaws in Mantis present significant risks, enabling remote code execution. Implement updates for enhanced security.
Multiple vulnerabilities have been discovered in Mantis, the most severe of which leading to the remote execution of arbitrary code.

Summary

Gentoo Linux Security Advisory GLSA 200812-07 https://security.gentoo.org/ Severity: High Title: Mantis: Multiple vulnerabilities Date: December 02, 2008 Bugs: #238570, #241940, #242722 ID: 200812-07

Synopsis ======= Multiple vulnerabilities have been discovered in Mantis, the most severe of which leading to the remote execution of arbitrary code.
Background ========= Mantis is a PHP/MySQL/Web based bugtracking system.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/mantisbt < 1.1.4-r1 >= 1.1.4-r1
========== Multiple issues have been reported in Mantis:
* EgiX reported that manage_proj_page.php does not correctly sanitize the sort parameter before p...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3860077_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here