Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20141208151353.GB29797@mail.corp.redhat.com>
Date: Mon, 8 Dec 2014 16:13:53 +0100
From: Vasyl Kaigorodov <vkaigoro@...hat.com>
To: oss-security@...ts.openwall.com
Subject: Re: MantisBT 1.2.18 Released

Hi Damien,

Thanks for posting this announcement.
Since this is public now - can we please have more information about
#17243/CVE-2014-8553? I can't find this CVE assignment on oss-sec, and
also the corresponding bug is marked private.

Thanks.
-- 
Vasyl Kaigorodov | Red Hat Product Security
PGP:  0xABB6E828 A7E0 87FF 5AB5 48EB 47D0 2868 217B F9FC ABB6 E828
On Sun, 07 Dec 2014, Damien Regad wrote:

> Greetings,
> 
> Please see the announcement below. This release fixes a number of CVEs I
> requested over the past few weeks (plus a few others). See the announcement
> for further details.
> 
> D. Regad
> 
> 
> -------- Forwarded Message --------
> Subject: 	MantisBT 1.2.18 Released
> Date: 	Fri, 5 Dec 2014 19:50:40 -0800
> Newsgroups: 	gmane.comp.bug-tracking.mantis.devel
> 
> 
> 
> MantisBT 1.2.18 is an important security update for the stable 1.2.x branch.
> All installations that are currently running any 1.2.x version are strongly
> advised to upgrade to this release. Download it from [2].
> 
> This release resolves a total of 43 issues, including fixes for 23 security-
> related bugs and vulnerabilities:
> 
> -  7 Cross-Site Scripting (XSS) issues: #17297/CVE-2014-9272,
>    #17583/CVE-2014-9270, #17870/CVE-2014-8987, #17874/CVE-2014-9271,
>    #17876/CVE-2014-9281, #17889/CVE-2014-8986, #17890/CVE-2014-9269
> 
> -  2 Code injection issues: #17725/CVE-2014-7146, #17875/CVE-2014-9280
> 
> -  2 SQL injection (XSS) issues: #17812/CVE-2014-8554, #17841/CVE-2014-9089
> 
> -  5 Information disclosure issues: #9885, #17744, #17877/CVE-2014-9279,
>    #17742/CVE-2014-8988, #17243/CVE-2014-8553
> 
> -  7 Other security issues: #10966, #17338, #17640/CVE-2014-6387,
>    #17648/CVE-2014-6316, #17780/CVE-2014-8598, #17811/CVE-2014-9117, #17878
> 
> Please refer to the changelog [1] on the MantisBT web site for complete
> details
> on each of these issues.
> 
> We would like to thank the following individuals and organizations for their
> valued contribution in discovering and fixing these issues, in no particular
> order: Mati Aharoni from Offensive Security and their bug bounty program,
> Matthias Karlsson, Matthew Daley, Egidio Romano, Florian Fuchs, Shahee
> Mirza,
> Oleg K, Alejo Popovici, Edwin Gozeling, Paul Richards, Roland Becker,
> Victor Boctor and Damien Regad.
> 
> 
> [1] http://www.mantisbt.org/bugs/changelog_page.php?version_id=191
> [2] http://sourceforge.net/projects/mantisbt/files/mantis-stable/
> 
> Thanks,
> MantisBT Team
> 
> 
> 

Content of type "application/pgp-signature" skipped

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.