Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
89

Fedora: 2015-12012 Critical: Mantis Security Vulnerability Fix Released

Security fix for CVE-2015-5059. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12011 2015-07-28 22:47:44 -------------------------------------------------------------------------------- Name : mantis Product : Fedora 22 Version : 1.2.19 Release : 3.fc22 URL : https://mantisbt.org/ Summary : Web-based issue tracking system Description : Mantis is a free popular web-based issue tracking system. It is written in the PHP scripting language and works with MySQL, MS SQL, and PostgreSQL databases and a web server. Almost any web browser should be able to function as a client. Documentation can be found in: /usr/share/doc/mantis When the package has finished installing, you will need to perform some additional configuration steps; these are described in: /usr/share/doc/mantis/README.Fedora -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-5059 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 23 2015 Gianluca Sforna - 1.2.19-3 - apply upstream patch for CVE-2015-5059 (#1237199) * Wed Jun 17 2015 Fedora Release Engineering - 1.2.19-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1237199 - CVE-2015-5059 mantis: information disclosure due to too wide $g_view_proj_doc_threshold permission https://bugzilla.redhat.com/show_bug.cgi?id=1237199 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mantis' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Important security patch for Mantis on Fedora 22 tackling the information exposure flaw CVE-2015-5059.. Mantis Security Fix,Fedora 22 Update,CVE-2015-5059,Information Disclosure,Software Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 07, 2015 Critical Fedora
89

Fedora 21 FEDORA-2015-12010 Critical: Mantis Information Disclosure

Security fix for CVE-2015-5059. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12010 2015-07-28 22:47:42 -------------------------------------------------------------------------------- Name : mantis Product : Fedora 21 Version : 1.2.19 Release : 3.fc21 URL : https://mantisbt.org/ Summary : Web-based issue tracking system Description : Mantis is a free popular web-based issue tracking system. It is written in the PHP scripting language and works with MySQL, MS SQL, and PostgreSQL databases and a web server. Almost any web browser should be able to function as a client. Documentation can be found in: /usr/share/doc/mantis When the package has finished installing, you will need to perform some additional configuration steps; these are described in: /usr/share/doc/mantis/README.Fedora -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-5059 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 23 2015 Gianluca Sforna - 1.2.19-3 - apply upstream patch for CVE-2015-5059 (#1237199) * Wed Jun 17 2015 Fedora Release Engineering - 1.2.19-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Mon Jan 26 2015 Gianluca Sforna - 1.2.19-1 - new upstream release - rebase patch - fix CVE-2014-9571, CVE-2014-9572, CVE-2014-9573 (#1183595) * Tue Dec 9 2014 Gianluca Sforna - 1.2.18-1 - new upstream release - drop upstreamed patches - fix several security issues, full list in upstream changelog: https://mantisbt.org/bugs/login_page.php?return=%2Fbugs%2Fchangelog_page.php * Fri Nov 14 2014 Gianluca Sforna - 1.2.17-4 - fix CVE-2014-7146, CVE-2014-8598 (#1162046) - fix CVE-2014-8554 (#1159295) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1237199 - CVE-2015-5059 mantis: information disclosure due to too wide$g_view_proj_doc_threshold permission https://bugzilla.redhat.com/show_bug.cgi?id=1237199 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mantis' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Urgent security update for Fedora 21 regarding sensitive data exposure in Mantis. Users are advised to implement the update immediately.. Fedora 21 Advisory,Mantis Security Update,Critical Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 07, 2015 Critical Fedora
87

Debian: DSA-3030-1 Critical: Mantis SQL Injection Threats Resolved

Multiple SQL injection vulnerabilities have been discovered in the Mantis bug tracking system. For the stable distribution (wheezy), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3030-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff September 20, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mantis CVE ID : CVE-2014-1608 CVE-2014-1609 Multiple SQL injection vulnerabilities have been discovered in the Mantis bug tracking system. For the stable distribution (wheezy), these problems have been fixed in version 1.2.11-1.2+deb7u1. We recommend that you upgrade your mantis packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several vulnerabilities addressed for Mantis; please update your packages to ensure a reliable Debian environment.. Mantis Update, SQL Injection Patch, Debian Security, Software Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 20, 2014 Critical Debian
87

Debian: DSA-2500-1 Moderate: Mantis Remote Access Issues

Several vulnerabilities were discovered in Mantis, am issue tracking system. CVE-2012-1118 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2500-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer June 24, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mantis Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2012-1118 CVE-2012-1119 CVE-2012-1120 CVE-2012-1122 CVE-2012-1123 CVE-2012-2692 Several vulnerabilities were discovered in Mantis, am issue tracking system. CVE-2012-1118 Mantis installation in which the private_bug_view_threshold configuration option has been set to an array value do not properly enforce bug viewing restrictions. CVE-2012-1119 Copy/clone bug report actions fail to leave an audit trail. CVE-2012-1120 The delete_bug_threshold/bugnote_allow_user_edit_delete access check can be bypassed by users who have write access to the SOAP API. CVE-2012-1122 Mantis performed access checks incorrectly when moving bugs between projects. CVE-2012-1123 A SOAP client sending a null password field can authenticate as the Mantis administrator. CVE-2012-2692 Mantis does not check the delete_attachments_threshold permission when a user attempts to delete an attachment from an issue. For the stable distribution (squeeze), these problems have been fixed in version 1.1.8+dfsg-10squeeze2. For the testing distribution (wheezy) and the unstable distribution (sid), these problems have been fixed in version 1.2.11-1. We recommend that you upgrade your mantis packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list:This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple weaknesses in Mantis call for prompt patches to maintain security standards and user protection on Debian platforms.. Debian Mantis Security Remote Access Configuration. . LinuxSecurity.com Team

Calendar%202 Jun 24, 2012 Debian
87

Debian: DSA-2308-1 Critical: Mantis Input Validation Threat

Several vulnerabilities were found in Mantis, a web-based bug tracking system: Insufficient input validation could result in local file inclusion and cross-site scripting. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2308-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff September 12, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mantis Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2011-3357 CVE-2011-3358 Debian Bug : 640297 Several vulnerabilities were found in Mantis, a web-based bug tracking system: Insufficient input validation could result in local file inclusion and cross-site scripting. For the oldstable distribution (lenny), this problem has been fixed in version 1.1.6+dfsg-2lenny6. For the stable distribution (squeeze), this problem has been fixed in version 1.1.8+dfsg-10squeeze1. For the unstable distribution (sid), this problem has been fixed in version 1.2.7-1. We recommend that you upgrade your mantis packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ensure your infrastructure is updated in accordance with the Ubuntu notification regarding a WordPress update that fixes severe security flaws in user authentication.. Debian Mantis Update, Input Validation Flaws, Bug Tracking Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 12, 2011 Critical Debian
87

Debian 5.0 Lenny DSA-1856-1 Moderate: Mantis Information Leak

It was discovered that the Debian Mantis package, a web based bug tracking system, installed the database credentials in a file with world-readable permissions onto the local filesystem. This allows local users to acquire the credentials used to control the Mantis . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1856-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst August 08, 2009 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : mantis Vulnerability : information leak Problem type : local Debian-specific: yes Debian Bug : 425010 It was discovered that the Debian Mantis package, a web based bug tracking system, installed the database credentials in a file with world-readable permissions onto the local filesystem. This allows local users to acquire the credentials used to control the Mantis database. This updated package corrects this problem for new installations and will carefully try to update existing ones. Administrators can check the permissions of the file /etc/mantis/config_db.php to see if they are safe for their environment. The old stable distribution (etch) does not contain a mantis package. For the stable distribution (lenny), this problem has been fixed in version 1.1.6+dfsg-2lenny1. For the unstable distribution (sid), this problem has been fixed in version 1.1.8+dfsg-2. We recommend that you upgrade your mantis package. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the properconfiguration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Source archives: Size/MD5 checksum: 2044082 429853b8caacc9e713b686524524418a Size/MD5 checksum: 1208 f77403f035efa94936500520fe273692 Size/MD5 checksum: 45118 68a32687bce135f3032a184c8ebf788f Architecture independent packages: Size/MD5 checksum: 1744390 7a7ff3cd017be50fa3ba162ac82eb3de These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian bulletin DSA-1897-2 concerns vulnerability in Asterisk software. Users are urged to update for system integrity.. Debian Mantis Package Update, Local Access Information Leak, Debian Security Fix. . LinuxSecurity.com Team

Calendar%202 Aug 08, 2009 Debian
91

Gentoo: GLSA-200803-04 Low Severity: Mantis Cross-Site Scripting Flaw

A persistent Cross-Site Scripting vulnerability has been discovered in Mantis.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200803-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Mantis: Cross-Site Scripting Date: March 03, 2008 Bugs: #203791 ID: 200803-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A persistent Cross-Site Scripting vulnerability has been discovered in Mantis. Background ========= Mantis is a web-based bug tracking system. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/mantisbt < 1.0.8-r1 > = 1.0.8-r1 Description ========== seiji reported that the filename for the uploaded file in bug_report.php is not properly sanitised before being stored. Impact ===== A remote attacker could upload a file with a specially crafted to a bug report, resulting in the execution of arbitrary HTML and script code within the context of the users's browser. Note that this vulnerability is only exploitable by authenticated users. Workaround ========= There is no known workaround at this time. Resolution ========= All Mantis users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-apps/mantisbt-1.0.8-r1" References ========= [ 1 ] CVE-2007-6611 https://www.cve.org/CVERecord?id=CVE-2007-6611 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo SecurityWebsite: https://security.gentoo.org/glsa/200803-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2008 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.7 (GNU/Linux) Comment: Using GnuPG with Mozilla - iD8DBQFHzHCtuhJ+ozIKI5gRAnPeAJ4jT1zqcc/xxiGeF3pfMzi/yZznvgCgolXY mo0mgPPgKLcwm2vE4h7kOKY=6gN6 -----END PGP SIGNATURE----- . A minor Cross-Site Scripting flaw identified in Mantis impacts Gentoo systems. Update required for security.. Mantis Security,Gentoo Advisory,Cross-Site Scripting,Web App Security,Attack Prevention. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Mar 03, 2008 Low Gentoo
87

Debian: DSA 905-1 Security Updates for Mantis Remote Vulnerabilities

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 905-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze November 22nd, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : mantis Vulnerability : several Problem type : remote Debian-specific: no CVE IDs : CVE-2005-3091 CVE-2005-3335 CVE-2005-3336 CVE-2005-3338 CVE-2005-3339 Debian Bugs : 330682 335938 Several security related problems have been discovered in Mantis, a web-based bug tracking system. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-3091 A cross-site scripting vulnerability allows attackers to inject arbitrary web script or HTML. CVE-2005-3335 A file inclusion vulnerability allows remote attackers to execute arbitrary PHP code and include arbitrary local files. CVE-2005-3336 An SQL injection vulnerability allows remote attackers to execute arbitrary SQL commands. CVE-2005-3338 Mantis can be tricked into displaying the otherwise hidden real mail address of its users. The old stable distribution (woody) is not affected by these problems. For the stable distribution (sarge) these problems have been fixed in version 0.19.2-4.1. For the unstable distribution (sid) these problems have been fixed in version 0.19.3-0.1. We recommend that you upgrade your mantis package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use anautomated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 572 b7c83d901ff3cfa1c4cb54502e5519c7 Size/MD5 checksum: 36447 e364d9ebb64a2071c3188baabb027dbd Size/MD5 checksum: 1298615 042c42c6de3bc536181391c1e9b25db3 Architecture independent components: Size/MD5 checksum: 895006 4131ad481a77292789af31e00a7960e6 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notice DSA 906-1 details various patches for WordPress aimed at resolving severe vulnerabilities.. Debian Security Advisory,Mantis Security Fixes,Remote Threats. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 22, 2005 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200