MantisBT: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201211-01 / MantisBT |
| Release Date |
November 08, 2012 |
| Latest Revision |
November 08, 2012: 1 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| www-apps/mantisbt |
<
1.2.11 |
>=
1.2.11 |
All supported architectures
|
Related bugreports:
#348761, #381417, #386153, #407121, #420375
Synopsis
Multiple vulnerabilities have been found in MantisBT, the worst of
which allowing for local file inclusion.
2.
Impact Information
Background
MantisBT is a PHP/MySQL/Web based bugtracking system.
Description
Multiple vulnerabilities have been discovered in MantisBT. Please review
the CVE identifiers referenced below for details.
Impact
A remote attacker could exploit these vulnerabilities to conduct
directory traversal attacks, disclose the contents of local files, inject
arbitrary web scripts, obtain sensitive information, bypass
authentication and intended access restrictions, or manipulate bugs and
attachments.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All MantisBT users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/mantisbt-1.2.11"
|
4.
References
|