Your message dated Mon, 28 Jan 2008 19:52:17 +0000
with message-id <[EMAIL PROTECTED]>
and subject line Bug#458377: fixed in mantis 0.19.2-5sarge5
has caused the attached Bug report to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere.  Please contact me immediately.)

Debian bug tracking system administrator
(administrator, Debian Bugs database)

--- Begin Message ---
Package: mantis
Severity: important
Tags: security patch

Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for matnis.

Advisory[0]:
| seiji has discovered a vulnerability in Mantis, which can be exploited by
| malicious users to conduct script insertion attacks.
| 
| Input passed as the filename for the uploaded file in bug_report.php is not
| properly sanitised before being stored. This can be exploited to insert
| arbitrary HTML and script code, which is executed in a user's browser session
| in context of an affected site when the malicious filename is viewed in
| view.php.
| 
| Successful exploitation requires valid user credentials.

The following patch fixes the problem:
http://www.mantisbt.org/bugs/file_download.php?file_id=1591&type=bug

If you fix this vulnerability please also include the CVE id
in your changelog entry.

For further information:
[0] http://secunia.com/advisories/28185/

Kind regards
Nico

-- 
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.

Attachment: pgpXk2yaUWlox.pgp
Description: PGP signature


--- End Message ---
--- Begin Message ---
Source: mantis
Source-Version: 0.19.2-5sarge5

We believe that the bug you reported is fixed in the latest version of
mantis, which is due to be installed in the Debian FTP archive:

mantis_0.19.2-5sarge5.diff.gz
  to pool/main/m/mantis/mantis_0.19.2-5sarge5.diff.gz
mantis_0.19.2-5sarge5.dsc
  to pool/main/m/mantis/mantis_0.19.2-5sarge5.dsc
mantis_0.19.2-5sarge5_all.deb
  to pool/main/m/mantis/mantis_0.19.2-5sarge5_all.deb



A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [EMAIL PROTECTED],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Patrick Schoenfeld <[EMAIL PROTECTED]> (supplier of updated mantis package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [EMAIL PROTECTED])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.7
Date: Wed, 09 Jan 2008 10:24:53 +0100
Source: mantis
Binary: mantis
Architecture: source all
Version: 0.19.2-5sarge5
Distribution: oldstable-security
Urgency: high
Maintainer: Igor Genibel <[EMAIL PROTECTED]>
Changed-By: Patrick Schoenfeld <[EMAIL PROTECTED]>
Description: 
 mantis     - web-based bug tracking system
Closes: 402802 458377
Changes: 
 mantis (0.19.2-5sarge5) oldstable-security; urgency=high
 .
   * Maintainer upload for the security team
   * Fixed security issue CVE-2007-6611: "Upload File" Script
     insertion vulnerability by applying the patch from sid.
     (Closes: #458377)
   * Fixed security issue CVE-2006-6574: Custom Field Information Disclosure by
     backporting changes in history_api.php from sid
     (Closes: #402802)
   * Fixed security issue: Email notifications bypass security on custom fields
   * Fixed multiple XSS vulnerabilites by backporting changes from upstream
     version 1.0.7
Files: 
 176c95ad5f1142fcb9364540fd19eeea 874 web optional mantis_0.19.2-5sarge5.dsc
 b1c5f077e0046c5b33d77e99a2b4ffe5 46292 web optional 
mantis_0.19.2-5sarge5.diff.gz
 5708305cbd20cde4825b3adb7d72d3a1 898014 web optional 
mantis_0.19.2-5sarge5_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iQEVAwUBR4sVoWz0hbPcukPfAQJqMQf/QuiGvAL5OS//Vg5H8YmnYUHujP+I9qe7
eYaTODpsm6N8XhrUYYeiPO92bDYF8IfPJF+Novb2n/2qVoo/q5mV/UcYxeA3m2sw
p0/JdTZIFexifKN5Z/dsK36JH3UOQxSbTzJB5NrNMtypKS9wAkemk0M8EJynKWb+
Te6qdnQNDDAGkNBUBog99xaRz3cqhUCx+Um3pbEO60igzwwoEMb2d4yi1XEqJiKF
qR0HQtu8DnYrMyZ832QOY+56Ju4qY6xfn+RxCqqyu6LmeEI1cUY72VI2t7IuWNKA
Dr2WdF10Eutg958hb1tXCkpgXz1xfxNMDw/YQ8AHQliSJ0UkHun/FA==
=kp5F
-----END PGP SIGNATURE-----



--- End Message ---

Reply via email to