Package: mantis
Version: 0.19.2-5sarge2
Severity: important
Tags: security

Hello,

While looking at the mantis security situation for sarge, I discovered
that the following CVE id's have not yet been fixed in sid. I'm not yet
sure of their status so I'm setting this as important now.

CVE-2006-0841
Multiple cross-site scripting (XSS) vulnerabilities in Mantis 1.00rc4
and earlier allow remote attackers to inject arbitrary web script or
HTML via the (1) hide_status, (2) handler_id, (3) user_monitor, (4)
reporter_id, (5) view_type, (6) show_severity, (7) show_category, (8)
show_status, (9) show_resolution, (10) show_build, (11) show_profile,
(12) show_priority, (13) highlight_changed, (14) relationship_type, and
(15) relationship_bug parameters in (a) view_all_set.php; the (16) sort
parameter in (b) manage_user_page.php; the (17) view_type parameter in
(c) view_filters_page.php; and the (18) title parameter in (d)
proj_doc_delete.php. NOTE: item 17 might be subsumed by CVE-2005-4522.

CVE-2006-0840
manage_user_page.php in Mantis 1.00rc4 and earlier does not properly
handle a sort parameter containing a ' (quote) character, which allows
remote attackers to trigger a SQL error that may be repeatedly reported
to a user who makes subsequent web accesses with the
MANTIS_MANAGE_COOKIE cookie. NOTE: this issue might be the same as
vector 2 in CVE-2005-4519.

CVE-2006-0665
Unspecified vulnerability in (1) query_store.php and (2)
manage_proj_create.php in Mantis before 1.0.0 has unknown impact and
attack vectors. NOTE: the provenance of this information is unknown; the
details are obtained solely from third party information. An original
vendor bug report is referenced, but not accessible to the general
public.

CVE-2006-0664
Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in
Mantis before 1.0 allows remote attackers to inject arbitrary web script
or HTML via unknown attack vectors. NOTE: the provenance of this
information is unknown; the details are obtained solely from third party
information. An original vendor bug report is referenced, but not
accessible to the general public.

Since there hasn't been a maintainer response to #361138 /
CVE-2006-1577, I'll probably prepare an NMU for that and these issues,
because I'm already researching them. Please voice any concerns right
away.


Thijs

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to