|
Message-ID: <50A290DF.9030701@redhat.com> Date: Tue, 13 Nov 2012 11:26:39 -0700 From: Kurt Seiifried <kseifried@...hat.com> To: oss-security@...ts.openwall.com Subject: Re: CVE request: mantis before 1.2.12 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 11/13/2012 07:52 AM, Hanno Böck wrote: > http://www.mantisbt.org/bugs/changelog_page.php?version_id=150 > > New mantis bugtracker release. Two fixes are security relevant > (althouhg both sound minor) Just to confirm I understand these issues: > - 0014496: [security] Workflow Transitions: Minimal Access Level > to Change to this status has no correct 'default' (dregad) - > resolved. http://www.mantisbt.org/bugs/view.php?id=14496 This is an information disclosure: "Consequently, saving the page without changes would cause the config to be saved with all access levels as 'viewer'." > - 0014704: [security] Clone and Move issue with Copy bug notes - > user get email notice from project without access (dregad) - > closed. http://www.mantisbt.org/bugs/view.php?id=14704 Also an information disclosure: Now any action on IssueB eg. add notes, change status causes send email notice to UserA from IssueB. UserA don't have access to IssueB by can read whole history and any notes from email body. > Please assign CVEs. - -- Kurt Seifried Red Hat Security Response Team (SRT) PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://www.enigmail.net/ iQIcBAEBAgAGBQJQopDeAAoJEBYNRVNeJnmTqjkQAKExE/IU6vY0WMd4LhD8CgYx 22caC6AeEHHHH0RZqPENosv94iMGgUlSuaHDEO1qNzWUwhCvP/gbP9JmOuKJ2dXh uHg4y4l8kpDrdC6GHGTCIYmCh+Y+Xu4+ZnVlSdrb8cw/GB1YdekMD/oaHt5eOfox 0cQ2HIN/4+deM0NRsomK+mTmZgajcsv1WTshhWPq8TsuZe8JdRr725A8vMTwRXa+ utKwdli/kCRmFTonbIZprnnNVrGRa0WctDZ8Tif3nBPyAD5SM1RFuKbvBH75D2aA xBagPxeQe/A2y2eBuzfrKdnIMnTZqcz42zPirnjCTydOX1dzMc24FSObsnzxLk86 vJK8hZlVnrFHL995i/1CC4P6IRx3FdKymNbXv7qYxf+UKImN/+uuwPLQYh575Tu3 ilf/yUKrrJgzS3qBZm67944Yv6tKMMZI0elwZ8KkXC4m7IjJG34f0BCBjZU4+34B EMguOYUXoHca7X1ViG6mC2HLMibF6gOXPYx5aEvLnpDwj4GUMskOE7IYCjFL9PaJ aPh2ZsFeRw++289eI9OEA5iNOJkSCI+g6Cy52KLwB/6XpKyR8gzISq1oYCA1dxDU Lrk31W+Y2bq83B7+cfN7+Uuu1VKQACsN96Uf/y53RccsZ+fYj/gKjom8c2PHd0D9 +wvcShflrjTOX8bfbbcg =pMX1 -----END PGP SIGNATURE-----
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.