Your message dated Fri, 15 Jun 2012 16:18:53 +0000
with message-id <[email protected]>
and subject line Bug#676783: fixed in mantis 1.2.11-1
has caused the Debian Bug report #676783,
regarding <mantisbt-1.2.11 multiple vulnerabilities
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
676783: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=676783
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: mantis
Version: 1.2.10-1
Severity: important
Tags: security patch upstream fixed-upstream
Hi Sils,
The MantisBT project has just released MantisBT 1.2.11 which fixes 2
vulnerabilities as per the [email protected] notice at
[1].
These issues are repeated below for your information (to help you decide
whether they affect Debian's default MantisBT configuration):
CVE REQUEST #1
Title: Reporters can edit arbitrary bugnotes via SOAP API
Affected: MantisBT 1.2.10 and earlier versions
Not affected: MantisBT 1.2.11
Description:
Roland Becker and Damien Regad (MantisBT developers) found that any user
able to report issues via the SOAP interface could also modify any
bugnotes (comments) created by other users. In a default/typical
MantisBT installation, SOAP API is enabled and any user can sign up to
report new issues. This vulnerability therefore impacts upon many public
facing MantisBT installations.
CVE REQUEST #2
Title: delete_attachments_threshold not checked on attachment deletion
Affected: MantisBT 1.2.10 and earlier versions
Not affected: MantisBT 1.2.11
Description:
Roland Becker (MantisBT developer) found that the
delete_attachments_threshold permission was not being checked when a
user attempted to delete an attachment from an issue. The more generic
update_bug_threshold permission was being checked instead. MantisBT
administrators may have been under the false impression that their
configuration of the delete_attachments_threshold was successfully
preventing unwanted users from deleting attachments.
Patches for the first issue (SOAP bugnote editing): [4] and [5].
Patches for the second issue (attachment deletion): [6], [7] and [8].
The patches aren't the best in the world (my initial commits had a few
errors because I couldn't test SOAP API)... sorry.
Please advise if I can be of further assistance.
With thanks,
David Hicks
MantisBT Developer
#mantisbt irc.freenode.net
http://www.mantisbt.org/bugs/
[1] http://www.openwall.com/lists/oss-security/2012/06/09/1
[2] http://www.mantisbt.org/bugs/view.php?id=14340
[3] http://www.mantisbt.org/bugs/view.php?id=14016
[4]
http://github.com/mantisbt/mantisbt/commit/edc8142bb8ac0ac0df1a3824d78c15f4015d959e
[5]
http://github.com/mantisbt/mantisbt/commit/175d973105fe9f03a37ced537b742611631067e0
[6]
http://github.com/mantisbt/mantisbt/commit/ceafe6f0c679411b81368052633a63dd3ca06d9c
[7]
http://github.com/mantisbt/mantisbt/commit/628e93708fa7e35e751fd23863d207423a25c408
[8]
http://github.com/mantisbt/mantisbt/commit/c9314184f541f0e3e3b91b3533104e50292c3e68
signature.asc
Description: This is a digitally signed message part
--- End Message ---
--- Begin Message ---
Source: mantis
Source-Version: 1.2.11-1
We believe that the bug you reported is fixed in the latest version of
mantis, which is due to be installed in the Debian FTP archive:
mantis_1.2.11-1.debian.tar.gz
to main/m/mantis/mantis_1.2.11-1.debian.tar.gz
mantis_1.2.11-1.dsc
to main/m/mantis/mantis_1.2.11-1.dsc
mantis_1.2.11-1_all.deb
to main/m/mantis/mantis_1.2.11-1_all.deb
mantis_1.2.11.orig.tar.gz
to main/m/mantis/mantis_1.2.11.orig.tar.gz
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Dario Minnucci <[email protected]> (supplier of updated mantis package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Fri, 15 Jun 2012 18:02:34 +0200
Source: mantis
Binary: mantis
Architecture: source all
Version: 1.2.11-1
Distribution: unstable
Urgency: high
Maintainer: Silvia Alvarez <[email protected]>
Changed-By: Dario Minnucci <[email protected]>
Description:
mantis - web-based bug tracking system
Closes: 671639 676783
Changes:
mantis (1.2.11-1) unstable; urgency=high
.
* New upstream release (1.2.11)
- Urgency high because includes fixes for 2 CVEs
(upstream fixed in version 1.2.11) (Closes: #676783)
- CVE-2012-2691
- CVE-2012-2692
* debian/po:
- Added Italian translation of the debconf templates.
Thanks to Beatrice Torracca. (Closes: #671639)
Checksums-Sha1:
e40fba15432c14c58bfbb57ab2545171719d485f 1870 mantis_1.2.11-1.dsc
57f755342aa0f01015e21388b2ed01a9c72d38af 3439675 mantis_1.2.11.orig.tar.gz
620acc05123fd37c4b1f4e258c57dc42df37e849 56118 mantis_1.2.11-1.debian.tar.gz
c0735cab4cf355c4bfc6c332b20502ab74649baa 2181758 mantis_1.2.11-1_all.deb
Checksums-Sha256:
295715b30cc0550dbd06ca828f3d243b33a34d4c200ce496bed82e90983a6268 1870
mantis_1.2.11-1.dsc
abe5be37ea6e94796986a0bb2933bcb8945487b8e82b5414041c700fbf9de503 3439675
mantis_1.2.11.orig.tar.gz
9bbe920eede5667d601f0b363a5355b66bfc22ef3295e66659a9ea905894d4bf 56118
mantis_1.2.11-1.debian.tar.gz
801c6a864379a218a57ac6f46cadd4ef8abd377ebee5b50e0831053b9e6a3e20 2181758
mantis_1.2.11-1_all.deb
Files:
68634f18722d251cd62a46077d202776 1870 web optional mantis_1.2.11-1.dsc
52fbb9f05fd3ea8994957b28731edf5d 3439675 web optional mantis_1.2.11.orig.tar.gz
838bee618e3e21c84c9bc7e5662abb7c 56118 web optional
mantis_1.2.11-1.debian.tar.gz
3d96ad21a843af58bc81b9497fc780b6 2181758 web optional mantis_1.2.11-1_all.deb
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iQIcBAEBCAAGBQJP210PAAoJEKgvu4Pz1XAz6mQP/11wCSGV1ZuJ2MwBvmr50jWz
4cEzJxCQeGMMnlY07jPC6H+TzxNoEyZQA2QeYUE4TuXep66Cn0zhX7l8fY6tq0Hb
G6utCiLOX7cNhf0t7eenFAoa46Tnq0SiKvlI+APlzFxpihYzgeb5LHkX7bRL/lnz
VxE913iJiH2fhf6O9o6ALs9YUdx4nw3pcsJ/Uj5cbhWjGSMh27VFDLUBssyR8NNc
b9YjIRld9doitmHVf3hoI99MldKhlJ+AoJ7GHZvGWyCylZFDy/LVq428vK1UCLuA
UNnDC4AGMyqWKXyuo7RywsMoiMk1iqbdbt6WNabWCkHhnlrgaSEkxz1vKO5D+qp9
Pc1MHxekSqtb7GvOfGgxgUfXEcJ/r1ui3zoH+PNOfG1oP9LVqsF5dAHP95ayxsod
qx3bjQHdjt2mMtJ4GuJrKBriP+icyCLOK5ONp5sA5BNeXrr9QZAoK6/IQOsAuEC7
LcnvBtjPaDvlB/YGGmyMmI16lq+cF1ZCcHS4JbV4ZEX48/cZ/V3rD5tRaHe7y6Xq
s+ljwsrlv2emV0/Uw1RLet1dJfcwB0Hj6Qz1Q1J9giVeUJiXnANpJvNbgvmp8Ywy
9xfVP2PO7fkWXGS1NWUybdihWEhNl79yvGSoYts91LWZTVfI6TvWzIUtujWxCoy6
jGGPo2qvMR6ID5Wc3sIM
=6/ni
-----END PGP SIGNATURE-----
--- End Message ---