Lucene search

K
debianDebianDEBIAN:DSA-3120-1:2E08D
HistoryJan 06, 2015 - 8:35 p.m.

[SECURITY] [DSA 3120-1] mantis security update

2015-01-0620:35:26
lists.debian.org
21

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0.353

Percentile

97.2%


Debian Security Advisory DSA-3120-1 [email protected]
http://www.debian.org/security/ Moritz Muehlenhoff
January 06, 2015 http://www.debian.org/security/faq


Package : mantis
CVE ID : CVE-2014-6316 CVE-2014-7146 CVE-2014-8553 CVE-2014-8554
CVE-2014-8598 CVE-2014-8986 CVE-2014-8988 CVE-2014-9089
CVE-2014-9117 CVE-2014-9269 CVE-2014-9270 CVE-2014-9271
CVE-2014-9272 CVE-2014-9280 CVE-2014-9281 CVE-2014-9388

Multiple security issues have been found in the Mantis bug tracking
system, which may result in phishing, information disclosure, CAPTCHA
bypass, SQL injection, cross-site scripting or the execution of arbitrary
PHP code.

For the stable distribution (wheezy), these problems have been fixed in
version 1.2.18-1.

We recommend that you upgrade your mantis packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: [email protected]

OSVersionArchitecturePackageVersionFilename
Debian7allmantis< 1.2.18-1mantis_1.2.18-1_all.deb

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

AI Score

6.4

Confidence

High

EPSS

0.353

Percentile

97.2%