Your message dated Wed, 23 Jan 2008 17:15:15 +0100 (CET)
with message-id <[EMAIL PROTECTED]>
and subject line Bug#462245: mantis: CVE-2008-0404 cross site scripting
vulnerability on summary page
has caused the attached Bug report to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what I am
talking about this indicates a serious mail system misconfiguration
somewhere. Please contact me immediately.)
Debian bug tracking system administrator
(administrator, Debian Bugs database)
--- Begin Message ---
Source: mantis
Severity: important
Tags: security patch
Hi,
the following CVE (Common Vulnerabilities & Exposures) id was
published for mantis.
CVE-2008-0404[0]:
| Cross-site scripting (XSS) vulnerability in Mantis before 1.1.1 allows
| remote attackers to inject arbitrary web script or HTML via the "Most
| active bugs" summary.
You can find a patch for this on:
http://mantisbt.svn.sourceforge.net/viewvc/mantisbt/trunk/mantisbt/core/summary_api.php?r1=4848&r2=4897&view=patch
If you fix this vulnerability please also include the CVE id
in your changelog entry.
For further information:
[0] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0404
Kind regards
Nico
--
Nico Golde - http://www.ngolde.de - [EMAIL PROTECTED] - GPG: 0x73647CFF
For security reasons, all text in this mail is double-rot13 encrypted.
pgp3BkEYCyKFH.pgp
Description: PGP signature
--- End Message ---
--- Begin Message ---
On Wed, January 23, 2008 16:54, Patrick Schoenfeld wrote:
> no, it does not affect sarge, nor does it affect sid. The thing is that
> this issue is affecting a part of mantis that has been added in mantis
> version 1.1.0a4 for the first time. Therefore it cannot affect previous
> versions. Besides that I did a (quick) check of the source code and
> couldn't find a similar piece of code. I therefore consider this to be
> unreproducible.
Yes, I've confirmed this in SVN. Thanks for your analysis, closing bug.
Thijs
--- End Message ---