Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Sun, 19 Oct 2008 11:18:31 +0200
From: Christian Hoffmann <hoffie@...too.org>
To: oss-security@...ts.openwall.com
Subject: CVE request: mantisbt < 1.1.4: RCE

Heya,

has a CVE id been already assigned to the recent remote code execution
issue in mantis < 1.1.4? If not, please do so.

References:
http://www.mantisbt.org/bugs/view.php?id=0009704
http://mantisbt.svn.sourceforge.net/viewvc/mantisbt/branches/BRANCH_1_1_0/mantisbt/core/utility_api.php?r1=5679&r2=5678&pathrev=5679
http://www.milw0rm.com/exploits/6768
https://bugs.gentoo.org/show_bug.cgi?id=242722


-- 
Christian Hoffmann


Download attachment "signature.asc" of type "application/pgp-signature" (261 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.