oss-sec mailing list archives
Re: CVE request: XSS in MantisBT
From: Damien Regad <dregad () mantisbt org>
Date: Mon, 16 Feb 2015 17:03:39 +0000 (UTC)
Paul, OK, fine, so your original commit fixed the problem and my subsequent fix reintroduced part of the issue. Sorry about that, but shit happens. It have been nice however, if you had tested the code back then (i.e. before 1.2.18 was released) instead of today, but anyway what's done is done. Now, the facts: - we don't have any single release with just cabacdc2 (or a port of it) in it so it's pointless arguing that it actually fixed the issue. - In 1.3, cabacdc2 + 3d0625d8 together form at least a *partial* fix for CVE-2014-8986 (released in 1.3.0-beta.1) - In 1.2, e326b73a is a combination of the above 2 (released in 1.2.18) Can you please test the commits attached to [1] and confirm that they do indeed fully address the original issue. @Mitre, please let us know whether this warrants a new CVE (following the same logic as in [2]) or if I should refer to the existing CVE-2014-8986 for this. [1] https://www.mantisbt.org/bugs/view.php?id=19301 [2] http://thread.gmane.org/gmane.comp.security.oss.general/14977/focus=15392
Current thread:
- CVE request: XSS in MantisBT Damien Regad (Feb 09)
- RE: CVE request: XSS in MantisBT P Richards (Feb 09)
- Re: CVE request: XSS in MantisBT Damien Regad (Feb 13)
- RE: Re: CVE request: XSS in MantisBT P Richards (Feb 13)
- Re: CVE request: XSS in MantisBT Damien Regad (Feb 16)
- RE: Re: CVE request: XSS in MantisBT P Richards (Feb 16)
- Re: CVE request: XSS in MantisBT Damien Regad (Feb 16)
- Re: CVE request: XSS in MantisBT Damien Regad (Feb 13)
- RE: CVE request: XSS in MantisBT P Richards (Feb 09)
- RE: CVE request: XSS in MantisBT P Richards (Feb 21)
- Re: CVE request: XSS in MantisBT cve-assign (Feb 21)