Lucene search

K
gentooGentoo FoundationGLSA-201211-01
HistoryNov 08, 2012 - 12:00 a.m.

MantisBT: Multiple vulnerabilities

2012-11-0800:00:00
Gentoo Foundation
security.gentoo.org
21

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.024

Percentile

90.1%

Background

MantisBT is a PHP/MySQL/Web based bugtracking system.

Description

Multiple vulnerabilities have been discovered in MantisBT. Please review the CVE identifiers referenced below for details.

Impact

A remote attacker could exploit these vulnerabilities to conduct directory traversal attacks, disclose the contents of local files, inject arbitrary web scripts, obtain sensitive information, bypass authentication and intended access restrictions, or manipulate bugs and attachments.

Workaround

There is no known workaround at this time.

Resolution

All MantisBT users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=www-apps/mantisbt-1.2.11"
OSVersionArchitecturePackageVersionFilename
Gentooanyallwww-apps/mantisbt< 1.2.11UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.024

Percentile

90.1%