oss-sec mailing list archives
CVE request: MantisBT <=1.2.3 (db_type) Local File Inclusion Vulnerability
From: David Hicks <hickseydr () optusnet com au>
Date: Wed, 15 Dec 2010 13:55:37 +1100
This is a CVE request for a vulnerability discovered in MantisBT <1.2.4 by Gjoko Krstic of Zero Science Lab as per the following advisory: http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4984.php MantisBT 1.2.4 has been released to resolve this issue. For distributions or users using MantisBT 1.1.x, the following patch can be applied: http://git.mantisbt.org/?p=mantisbt.git;a=commitdiff_plain;h=2641fdc60d2032ae1586338d6416e1eadabd7590 Please note that MantisBT 1.1.x is not recommended for use due to many security improvements and features implemented in MantisBT 1.2.x (but not backported to 1.1.x). Detailed information about this vulnerability can be found in this bug report: http://www.mantisbt.org/bugs/view.php?id=12607 Regards, David Hicks MantisBT Developer mantisbt.org, #mantishelp freenode
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- CVE request: MantisBT <=1.2.3 (db_type) Local File Inclusion Vulnerability David Hicks (Dec 15)
- Re: CVE request: MantisBT <=1.2.3 (db_type) Local File Inclusion Vulnerability Josh Bressers (Dec 16)