Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Security fix for CVE-2015-5059. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12011 2015-07-28 22:47:44 -------------------------------------------------------------------------------- Name : mantis Product : Fedora 22 Version : 1.2.19 Release : 3.fc22 URL : https://mantisbt.org/ Summary : Web-based issue tracking system Description : Mantis is a free popular web-based issue tracking system. It is written in the PHP scripting language and works with MySQL, MS SQL, and PostgreSQL databases and a web server. Almost any web browser should be able to function as a client. Documentation can be found in: /usr/share/doc/mantis When the package has finished installing, you will need to perform some additional configuration steps; these are described in: /usr/share/doc/mantis/README.Fedora -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-5059 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 23 2015 Gianluca Sforna - 1.2.19-3 - apply upstream patch for CVE-2015-5059 (#1237199) * Wed Jun 17 2015 Fedora Release Engineering - 1.2.19-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1237199 - CVE-2015-5059 mantis: information disclosure due to too wide $g_view_proj_doc_threshold permission https://bugzilla.redhat.com/show_bug.cgi?id=1237199 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mantis' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Security fix for CVE-2015-5059. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12010 2015-07-28 22:47:42 -------------------------------------------------------------------------------- Name : mantis Product : Fedora 21 Version : 1.2.19 Release : 3.fc21 URL : https://mantisbt.org/ Summary : Web-based issue tracking system Description : Mantis is a free popular web-based issue tracking system. It is written in the PHP scripting language and works with MySQL, MS SQL, and PostgreSQL databases and a web server. Almost any web browser should be able to function as a client. Documentation can be found in: /usr/share/doc/mantis When the package has finished installing, you will need to perform some additional configuration steps; these are described in: /usr/share/doc/mantis/README.Fedora -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-5059 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 23 2015 Gianluca Sforna - 1.2.19-3 - apply upstream patch for CVE-2015-5059 (#1237199) * Wed Jun 17 2015 Fedora Release Engineering - 1.2.19-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Mon Jan 26 2015 Gianluca Sforna - 1.2.19-1 - new upstream release - rebase patch - fix CVE-2014-9571, CVE-2014-9572, CVE-2014-9573 (#1183595) * Tue Dec 9 2014 Gianluca Sforna - 1.2.18-1 - new upstream release - drop upstreamed patches - fix several security issues, full list in upstream changelog: https://mantisbt.org/bugs/login_page.php?return=%2Fbugs%2Fchangelog_page.php * Fri Nov 14 2014 Gianluca Sforna - 1.2.17-4 - fix CVE-2014-7146, CVE-2014-8598 (#1162046) - fix CVE-2014-8554 (#1159295) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1237199 - CVE-2015-5059 mantis: information disclosure due to too wide$g_view_proj_doc_threshold permission https://bugzilla.redhat.com/show_bug.cgi?id=1237199 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mantis' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Multiple SQL injection vulnerabilities have been discovered in the Mantis bug tracking system. For the stable distribution (wheezy), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3030-1
Several vulnerabilities were discovered in Mantis, am issue tracking system. CVE-2012-1118 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2500-1
Several vulnerabilities were found in Mantis, a web-based bug tracking system: Insufficient input validation could result in local file inclusion and cross-site scripting. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2308-1
It was discovered that the Debian Mantis package, a web based bug tracking system, installed the database credentials in a file with world-readable permissions onto the local filesystem. This allows local users to acquire the credentials used to control the Mantis . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1856-1
A persistent Cross-Site Scripting vulnerability has been discovered in Mantis.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200803-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Mantis: Cross-Site Scripting Date: March 03, 2008 Bugs: #203791 ID: 200803-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A persistent Cross-Site Scripting vulnerability has been discovered in Mantis. Background ========= Mantis is a web-based bug tracking system. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/mantisbt < 1.0.8-r1 > = 1.0.8-r1 Description ========== seiji reported that the filename for the uploaded file in bug_report.php is not properly sanitised before being stored. Impact ===== A remote attacker could upload a file with a specially crafted to a bug report, resulting in the execution of arbitrary HTML and script code within the context of the users's browser. Note that this vulnerability is only exploitable by authenticated users. Workaround ========= There is no known workaround at this time. Resolution ========= All Mantis users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-apps/mantisbt-1.0.8-r1" References ========= [ 1 ] CVE-2007-6611 https://www.cve.org/CVERecord?id=CVE-2007-6611 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo SecurityWebsite: https://security.gentoo.org/glsa/200803-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 905-1
Get the latest Linux and open source security news straight to your inbox.