漏洞信息详情
Mantis自定义字段信息泄露漏洞
- CNNVD编号:CNNVD-200612-366
- 危害等级: 中危
- CVE编号:
CVE-2006-6574
- 漏洞类型:
资料不足
- 发布时间:
2006-12-15
- 威胁类型:
远程
- 更新时间:
2006-12-19
- 厂 商:
mantis - 漏洞来源:
Mantis -
漏洞简介
Mantis的1.1.0a2之前版本未对问题历史(Bug历史)实施按条目(per-item)访问控制,远程攻击者可以通过读取变更栏来获取敏感信息。如通过自定义字段的变更栏。
漏洞公告
目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:
Mantis Mantis 0.10
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.10.1
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.10.2
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.11
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.12
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.13
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.13.1
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.14
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.14.1
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.14.2
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.14.3
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.14.4
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.14.5
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.14.8
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.1
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.10
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.11
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.11
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.12
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.12
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.2
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.3
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.3
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.4
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.5
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.6
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.6
Mantis mantis-1.1.0a2.tar.gz
http://sourceforge.net/project/showfiles.php?group_id=14963&package_id =12175&release_id=469627
Mantis Mantis 0.15.7
Mantis mantis-1.1.0a2.ta
参考网址
来源: sourceforge.net
链接:http://sourceforge.net/project/shownotes.php?release_id=469627
来源: www.mantisbugtracker.com
链接:http://www.mantisbugtracker.com/changelog.php
来源: SECUNIA
名称: 23258
链接:http://secunia.com/advisories/23258
来源: MISC
链接:http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?view=log
来源: MISC
链接:http://mantisbt.cvs.sourceforge.net/mantisbt/mantisbt/core/history_api.php?r1=1.34&r2=1.35
来源: MISC
链接:http://bugs.mantisbugtracker.com/view.php?id=7364
来源: MISC
链接:http://bugs.mantisbugtracker.com/view.php?id=3375
来源: XF
名称: mantis-customfield-info-disclosure(30870)
链接:http://xforce.iss.net/xforce/xfdb/30870
来源: BID
名称: 21566
链接:http://www.securityfocus.com/bid/21566
来源: VUPEN
名称: ADV-2006-4978
链接:http://www.frsirt.com/english/advisories/2006/4978
来源: DEBIAN
名称: DSA-1467
链接:http://www.debian.org/security/2008/dsa-1467
来源: SECUNIA
名称: 28551