Bug#698481: mantis: multiple XSS vulnerabilities

2013-03-02 Thread Salvatore Bonaccorso
Control: retitle 698481 mantis: multiple XSS vulnerabilities (CVE-2013-0197, CVE-2013-1811) Hi On Sat, Jan 19, 2013 at 07:55:31AM +0100, Salvatore Bonaccorso wrote: > [3]: http://www.mantisbt.org/bugs/view.php?id=15258 (CVE requested) > http://marc.info/?l=oss-security&m=135855599401856&w

Bug#698481: mantis: multiple XSS vulnerabilities

2013-01-24 Thread Salvatore Bonaccorso
Hi there seems to be an additional XSS fixed affecting the 1.2.x branch (not checked): [1]: http://mantisbt.org/bugs/view.php?id=15416 and also [2] (but seems present only in 1.2.13). [2]: http://mantisbt.org/bugs/view.php?id=15415 Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bug

Bug#698481: mantis: multiple XSS vulnerabilities

2013-01-21 Thread Salvatore Bonaccorso
Hi Small followup: http://marc.info/?l=oss-security&m=135876600302683&w=2 Damien Regad mentions there that CVE-2013-0197 is also only affecting 1.2.12. Regards, Salvatore -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact lis

Bug#698481: mantis: multiple XSS vulnerabilities

2013-01-18 Thread Salvatore Bonaccorso
Package: mantis Severity: grave Tags: security Justification: user security hole -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi Some vulnerabilities in mantis where reported: [1]: http://www.mantisbt.org/bugs/view.php?id=15373 (CVE-2013-0197) http://marc.info/?l=oss-security&m=135853