[mantis] [CVE-2006-6574] [CVE-2007-6611] remote vulnerabilities

Bug #185021 reported by disabled.user
258
Affects Status Importance Assigned to Milestone
mantis (Debian)
Fix Released
Unknown
mantis (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Won't Fix
Undecided
Unassigned
Edgy
Won't Fix
Undecided
Unassigned
Feisty
Won't Fix
Undecided
Unassigned
Gutsy
Won't Fix
Undecided
Unassigned

Bug Description

Binary package hint: mantis

References:
DSA-1467-1 (http://www.debian.org/security/2008/dsa-1467)

Quoting:
"Several remote vulnerabilities have been discovered in Mantis, a web based
bug tracking system. The Common Vulnerabilities and Exposures project
identifies the following problems:

CVE-2006-6574

    Custom fields were not appropriately protected by per-item access
    control, allowing for sensitive data to be published.

CVE-2007-6611

    Multiple cross site scripting issues allowed a remote attacker to
    insert malicious HTML or web script into Mantis web pages."

CVE References

Changed in mantis:
status: Unknown → Fix Released
Revision history for this message
Michael Bienia (geser) wrote :

For hardy fixed in mantis 1.0.8-4.

Revision history for this message
William Grant (wgrant) wrote :

Feisty and Gutsy are only affected by CVE-2006-6574.

Revision history for this message
Hew (hew) wrote :

Ubuntu Edgy Eft is no longer supported, so a SRU will not be issued for this release. Marking Edgy as Won't Fix.

Changed in mantis:
status: New → Won't Fix
Changed in mantis:
status: New → Fix Released
status: New → Won't Fix
Changed in mantis:
status: New → Confirmed
Revision history for this message
Sergio Zanchetta (primes2h) wrote :

The 18 month support period for Gutsy Gibbon 7.10 has reached its end of life -
http://www.ubuntu.com/news/ubuntu-7.10-eol . As a result, we are closing the
Gutsy task.

Changed in mantis (Ubuntu Gutsy):
status: Confirmed → Won't Fix
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for reporting this bug to Ubuntu. dapper has reached EOL
(End of Life) and is no longer supported. As a result, this bug
against dapper is being marked "Won't Fix". Please see
https://wiki.ubuntu.com/Releases for currently supported Ubuntu
releases.

Please feel free to report any other bugs you may find.

Changed in mantis (Ubuntu Dapper):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.