oss-security December 2010 archive
Main Archive Page > Month Archives  > oss-security archives
oss-security: Re: [oss-security] CVE request: MantisBT <=1.2.

Re: [oss-security] CVE request: MantisBT <=1.2.3 (db_type) Local File Inclusion Vulnerability

From: Josh Bressers <bressers_at_nospam>
Date: Thu Dec 16 2010 - 13:59:22 GMT
To: oss-security@lists.openwall.com

Please use CVE-2010-4350.

Thanks.

-- JB ----- "David Hicks" <hickseydr@optusnet.com.au> wrote: > This is a CVE request for a vulnerability discovered in MantisBT > <1.2.4 > by Gjoko Krstic of Zero Science Lab as per the following advisory: > > http://www.zeroscience.mk/en/vulnerabilities/ZSL-2010-4984.php > > MantisBT 1.2.4 has been released to resolve this issue. > > For distributions or users using MantisBT 1.1.x, the following patch > can > be applied: > http://git.mantisbt.org/?p=mantisbt.git;a=commitdiff_plain;h=2641fdc60d2032ae1586338d6416e1eadabd7590 > > Please note that MantisBT 1.1.x is not recommended for use due to > many > security improvements and features implemented in MantisBT 1.2.x (but > not backported to 1.1.x). > > Detailed information about this vulnerability can be found in this > bug > report: http://www.mantisbt.org/bugs/view.php?id=12607 > > Regards, > > David Hicks > MantisBT Developer > mantisbt.org, #mantishelp freenode