Bug#330682: mantis: Several vulnerabilities in Mantis

2005-10-20 Thread Moritz Muehlenhoff
Hilko Bengen wrote: > >> mantis 1.0.0-rc2 fixed these security problems, that seem to be missing in > >> the latest DSA upload that fixed several others: > >> > >> - 0006097: [security] user ID is cached indefinately (thraxisp) > >> - 0006189: [security] List of users (in filter) visible for unaut

Bug#330682: mantis: Several vulnerabilities in Mantis

2005-10-19 Thread Luk Claes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Thijs Kinkhorst wrote: > Hello, Hi Thijs > On Thu, 29 Sep 2005, Moritz Muehlenhoff <[EMAIL PROTECTED]> wrote: > >>mantis 1.0.0-rc2 fixed these security problems, that seem to be missing in >>the latest DSA upload that fixed several others: >> >>- 00

Bug#330682: mantis: Several vulnerabilities in Mantis

2005-10-19 Thread Hilko Bengen
Thijs Kinkhorst <[EMAIL PROTECTED]> writes: > Hello, > > On Thu, 29 Sep 2005, Moritz Muehlenhoff <[EMAIL PROTECTED]> wrote: >> mantis 1.0.0-rc2 fixed these security problems, that seem to be missing in >> the latest DSA upload that fixed several others: >> >> - 0006097: [security] user ID is cach

Bug#330682: mantis: Several vulnerabilities in Mantis

2005-10-19 Thread Thijs Kinkhorst
Hello, On Thu, 29 Sep 2005, Moritz Muehlenhoff <[EMAIL PROTECTED]> wrote: > mantis 1.0.0-rc2 fixed these security problems, that seem to be missing in > the latest DSA upload that fixed several others: > > - 0006097: [security] user ID is cached indefinately (thraxisp) > - 0006189: [security] Lis

Bug#330682: mantis: Several vulnerabilities in Mantis

2005-09-29 Thread Moritz Muehlenhoff
Package: mantis Severity: grave Tags: security Justification: user security hole mantis 1.0.0-rc2 fixed these security problems, that seem to be missing in the latest DSA upload that fixed several others: - 0006097: [security] user ID is cached indefinately (thraxisp) - 0006189: [security] List o