From 4f2d7949f03e1c198bc888f2d05f421d35c57e21 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Mon, 9 Oct 2017 18:53:29 +0100 Subject: reinit the tree, so we can have metadata --- metadata/glsa/glsa-201211-01.xml | 78 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 78 insertions(+) create mode 100644 metadata/glsa/glsa-201211-01.xml (limited to 'metadata/glsa/glsa-201211-01.xml') diff --git a/metadata/glsa/glsa-201211-01.xml b/metadata/glsa/glsa-201211-01.xml new file mode 100644 index 000000000000..29b80098e15c --- /dev/null +++ b/metadata/glsa/glsa-201211-01.xml @@ -0,0 +1,78 @@ + + + + MantisBT: Multiple vulnerabilities + Multiple vulnerabilities have been found in MantisBT, the worst of + which allowing for local file inclusion. + + MantisBT + 2012-11-08 + 2012-11-08: 1 + 348761 + 381417 + 386153 + 407121 + 420375 + remote + + + 1.2.11 + 1.2.11 + + + +

MantisBT is a PHP/MySQL/Web based bugtracking system.

+
+ +

Multiple vulnerabilities have been discovered in MantisBT. Please review + the CVE identifiers referenced below for details. +

+
+ +

A remote attacker could exploit these vulnerabilities to conduct + directory traversal attacks, disclose the contents of local files, inject + arbitrary web scripts, obtain sensitive information, bypass + authentication and intended access restrictions, or manipulate bugs and + attachments. +

+
+ +

There is no known workaround at this time.

+
+ +

All MantisBT users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=www-apps/mantisbt-1.2.11" + + +
+ + CVE-2010-3303 + CVE-2010-3763 + CVE-2010-4348 + CVE-2010-4349 + CVE-2010-4350 + CVE-2011-2938 + CVE-2011-3356 + CVE-2011-3357 + CVE-2011-3358 + CVE-2011-3578 + CVE-2011-3755 + CVE-2012-1118 + CVE-2012-1119 + CVE-2012-1120 + CVE-2012-1121 + CVE-2012-1122 + CVE-2012-1123 + CVE-2012-2691 + CVE-2012-2692 + + + underling + + + keytoaster + +
-- cgit v1.2.3