| Summary: | www-apps/mantisbt < 1.0.8-r1 "Upload File" Script Insertion Vulnerability (CVE-2007-6611) | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | Pierre-Yves Rofes (RETIRED) <py> |
| Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED FIXED | ||
| Severity: | minor | CC: | lars, pva |
| Priority: | High | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://secunia.com/advisories/28185/ | ||
| Whiteboard: | B4 [glsa] | ||
| Package list: | Runtime testing required: | --- | |
|
Description
Pierre-Yves Rofes (RETIRED)
2007-12-30 18:11:39 UTC
maintainers, please bump as necessary. Fixed in mantisbt-1.0.8-r1. Arches, please test and mark stable www-apps/mantisbt-1.0.8-r1. Target keywords : "amd64 ppc x86" x86 stable *** Bug 204331 has been marked as a duplicate of this bug. *** can someone please add "CVE-2007-6611" to the summary? i dont have the needed permissions ppc stable amd64 stable This one is ready for GLSA vote. I tend to vote YES. Both mantis 1.1.0 and 1.1.1 have fixed additional security issues (CVE-2007-6611, CVE-2008-0404), maybe the glsa should wait for another stabilization-round? That's not necessary: take a look at bug 207260. Stabilization of mantisbt-1.1 is in my TODO list but it's rather fresh release, so I wouldn't be hurry. voting YES, glsa request filed. I would have vote no for this "authenticated" XSS but that's OK, 2 Yes / 1 No. Or to be more precise it's 1½/1½. tend usually means ½ :-) If registration is commonly open I'd say yes, if not then it would be NO. YES, was already filed. GLSA 200803-04 |