Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 13 Nov 2012 11:26:39 -0700
From: Kurt Seiifried <kseifried@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: CVE request: mantis before 1.2.12

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On 11/13/2012 07:52 AM, Hanno Böck wrote:
> http://www.mantisbt.org/bugs/changelog_page.php?version_id=150
> 
> New mantis bugtracker release. Two fixes are security relevant 
> (althouhg both sound minor)

Just to confirm I understand these issues:

> - 0014496: [security] Workflow Transitions: Minimal Access Level
> to Change to this status has no correct 'default' (dregad) -
> resolved. http://www.mantisbt.org/bugs/view.php?id=14496

This is an information disclosure: "Consequently, saving the page
without changes would cause the config to be saved with all access
levels as 'viewer'."

> - 0014704: [security] Clone and Move issue with Copy bug notes -
> user get email notice from project without access (dregad) -
> closed. http://www.mantisbt.org/bugs/view.php?id=14704

Also an information disclosure: Now any action on IssueB eg. add
notes, change status causes send email notice to UserA from IssueB.
UserA don't have access to IssueB by can read whole history and any
notes from email body.

> Please assign CVEs.




- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://www.enigmail.net/

iQIcBAEBAgAGBQJQopDeAAoJEBYNRVNeJnmTqjkQAKExE/IU6vY0WMd4LhD8CgYx
22caC6AeEHHHH0RZqPENosv94iMGgUlSuaHDEO1qNzWUwhCvP/gbP9JmOuKJ2dXh
uHg4y4l8kpDrdC6GHGTCIYmCh+Y+Xu4+ZnVlSdrb8cw/GB1YdekMD/oaHt5eOfox
0cQ2HIN/4+deM0NRsomK+mTmZgajcsv1WTshhWPq8TsuZe8JdRr725A8vMTwRXa+
utKwdli/kCRmFTonbIZprnnNVrGRa0WctDZ8Tif3nBPyAD5SM1RFuKbvBH75D2aA
xBagPxeQe/A2y2eBuzfrKdnIMnTZqcz42zPirnjCTydOX1dzMc24FSObsnzxLk86
vJK8hZlVnrFHL995i/1CC4P6IRx3FdKymNbXv7qYxf+UKImN/+uuwPLQYh575Tu3
ilf/yUKrrJgzS3qBZm67944Yv6tKMMZI0elwZ8KkXC4m7IjJG34f0BCBjZU4+34B
EMguOYUXoHca7X1ViG6mC2HLMibF6gOXPYx5aEvLnpDwj4GUMskOE7IYCjFL9PaJ
aPh2ZsFeRw++289eI9OEA5iNOJkSCI+g6Cy52KLwB/6XpKyR8gzISq1oYCA1dxDU
Lrk31W+Y2bq83B7+cfN7+Uuu1VKQACsN96Uf/y53RccsZ+fYj/gKjom8c2PHd0D9
+wvcShflrjTOX8bfbbcg
=pMX1
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.