Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.71478
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2500-1)
Summary:The remote host is missing an update for the Debian 'mantis' package(s) announced via the DSA-2500-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'mantis' package(s) announced via the DSA-2500-1 advisory.

Vulnerability Insight:
Several vulnerabilities were discovered in Mantis, an issue tracking system.

CVE-2012-1118

Mantis installation in which the private_bug_view_threshold configuration option has been set to an array value do not properly enforce bug viewing restrictions.

CVE-2012-1119

Copy/clone bug report actions fail to leave an audit trail.

CVE-2012-1120

The delete_bug_threshold/bugnote_allow_user_edit_delete access check can be bypassed by users who have write access to the SOAP API.

CVE-2012-1122

Mantis performed access checks incorrectly when moving bugs between projects.

CVE-2012-1123

A SOAP client sending a null password field can authenticate as the Mantis administrator.

CVE-2012-2692

Mantis does not check the delete_attachments_threshold permission when a user attempts to delete an attachment from an issue.

For the stable distribution (squeeze), these problems have been fixed in version 1.1.8+dfsg-10squeeze2.

For the testing distribution (wheezy) and the unstable distribution (sid), these problems have been fixed in version 1.2.11-1.

We recommend that you upgrade your mantis packages.

Affected Software/OS:
'mantis' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2012-1118
48258
http://secunia.com/advisories/48258
49572
http://secunia.com/advisories/49572
51199
http://secunia.com/advisories/51199
52313
http://www.securityfocus.com/bid/52313
DSA-2500
http://www.debian.org/security/2012/dsa-2500
FEDORA-2012-18273
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092926.html
FEDORA-2012-18294
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/093064.html
FEDORA-2012-18299
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/093063.html
GLSA-201211-01
http://security.gentoo.org/glsa/glsa-201211-01.xml
[oss-security] 20120306 Re: CVE request: mantisbt before 1.2.9
http://www.openwall.com/lists/oss-security/2012/03/06/9
http://www.mantisbt.org/bugs/changelog_page.php?version_id=140
http://www.mantisbt.org/bugs/view.php?id=10124
https://github.com/mantisbt/mantisbt/commit/eb803ed02105fc919cf5f789e939f2b824162927
Common Vulnerability Exposure (CVE) ID: CVE-2012-1119
http://www.mantisbt.org/bugs/view.php?id=13816
https://github.com/mantisbt/mantisbt/commit/cf5df427f17cf9204645f83e000665780eb9afe6
https://github.com/mantisbt/mantisbt/commit/dea7e315f3fc96dfa995e56e8810845fc07a47aa
Common Vulnerability Exposure (CVE) ID: CVE-2012-1120
http://www.mantisbt.org/bugs/view.php?id=13656
https://github.com/mantisbt/mantisbt/commit/df7782a65e96aa1c9639a7625a658102134c7fe0
Common Vulnerability Exposure (CVE) ID: CVE-2012-1122
http://www.mantisbt.org/bugs/view.php?id=13748
https://github.com/mantisbt/mantisbt/commit/0da3f7ace233208eb3c8d628cc2fd6e56d83839f
Common Vulnerability Exposure (CVE) ID: CVE-2012-1123
http://www.mantisbt.org/bugs/view.php?id=13901
https://github.com/mantisbt/mantisbt/commit/f5106be52cf6aa72c521f388e4abb5f0de1f1d7f
Common Vulnerability Exposure (CVE) ID: CVE-2012-2692
53921
http://www.securityfocus.com/bid/53921
[oss-security] 20120609 CVE requests (x2) for Mantis Bug Tracker (MantisBT) before 1.2.11
http://www.openwall.com/lists/oss-security/2012/06/09/1
[oss-security] 20120611 Re: CVE requests (x2) for Mantis Bug Tracker (MantisBT) before 1.2.11
http://www.openwall.com/lists/oss-security/2012/06/11/6
http://www.mantisbt.org/bugs/changelog_page.php?version_id=148
http://www.mantisbt.org/bugs/view.php?id=14016
https://github.com/mantisbt/mantisbt/commit/ceafe6f0c679411b81368052633a63dd3ca06d9c
CopyrightCopyright (C) 2012 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.