[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

UNIRAS Brief - 654/05 - Debian - New mantis packages fix several vulnerabilities [DSA 778-1]



 
-----BEGIN PGP SIGNED MESSAGE-----

- ----------------------------------------------------------------------------------
   UNIRAS (UK Govt CERT) Briefing Notice - 654/05 dated 19.08.05  Time: 16:20  
  UNIRAS is part of NISCC (National Infrastructure Security Co-ordination Centre)
- ---------------------------------------------------------------------------------- 
  UNIRAS material is also available from its website at www.uniras.gov.uk and
         Information about NISCC is available from www.niscc.gov.uk
- ----------------------------------------------------------------------------------

Title
=====
Debian - New mantis packages fix several vulnerabilities  [DSA 778-1]


Detail
====== 

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - --------------------------------------------------------------------------
Debian Security Advisory DSA 778-1                     security@xxxxxxxxxx
http://www.debian.org/security/                             Martin Schulze
August 19th, 2005                       http://www.debian.org/security/faq
- - --------------------------------------------------------------------------

Package        : mantis
Vulnerability  : missing input sanitising
Problem-Type   : remote
Debian-specific: no
CVE ID         : CAN-2005-2556 CAN-2005-2557

Two security related problems have been discovered in Mantis, a
web-based bug tracking system.  The Common Vulnerabilities and
Exposures project identifies the following problems:

CAN-2005-2556

    A remote attacker could insert arbitrary SQL code into SQL
    statements.

CAN-2005-2557

    A remote attacker was able to insert arbitrary HTML code bug
    reports, hence, cross site scripting.

The old stable distribution (woody) does not seem to be affected by
these problems.

For the stable distribution (sarge) these problems have been fixed in
version 0.19.2-4.

For the unstable distribution (sid) these problems have been fixed in
version 0.19.2-4.

We recommend that you upgrade your mantis package.


Upgrade Instructions
- - --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.1 alias sarge
- - --------------------------------

  Source archives:

    http://security.debian.org/pool/updates/main/m/mantis/mantis_0.19.2-4.dsc
      Size/MD5 checksum:      568 645a849f54cada06624b040ca106310f
    http://security.debian.org/pool/updates/main/m/mantis/mantis_0.19.2-4.diff.gz
      Size/MD5 checksum:    34601 311c66f058bfd06ef02d97dc0dad4880
    http://security.debian.org/pool/updates/main/m/mantis/mantis_0.19.2.orig.tar.gz
      Size/MD5 checksum:  1298615 042c42c6de3bc536181391c1e9b25db3

  Architecture independent components:

    http://security.debian.org/pool/updates/main/m/mantis/mantis_0.19.2-4_all.deb
      Size/MD5 checksum:   895224 afa2f33377b412779d5710e94b5f68e3


  These files will probably be moved into the stable distribution on
  its next update.

- - ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@xxxxxxxxxxxxxxxx
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>

- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFDBeXcW5ql+IAeqTIRAnZVAKCz19oHpGJt//rRjb6PaPkKGnlQFACfTK4j
kveWIZjiSoKyZ1d8A8xetEA=
=iS8/
- -----END PGP SIGNATURE-----


- ----------------------------------------------------------------------------------

For additional information or assistance, please contact the HELP Desk by 
telephone or Not Protectively Marked information may be sent via 
EMail to: uniras@xxxxxxxxxxxx

Office Hours:
Mon - Fri: 08:30 - 17:00 Hrs
Tel: +44 (0) 870 487 0748 Ext 4511
Fax: +44 (0) 870 487 0749

Outside of Office Hours:
On Call Duty Officer:
Tel: +44 (0) 870 487 0748 and follow the prompts

- ----------------------------------------------------------------------------------
UNIRAS wishes to acknowledge the contributions of Debian for the information 
contained in this Briefing. 
- ----------------------------------------------------------------------------------
This Briefing contains the information released by the original author. Some 
of the information may have changed since it was released. If the vulnerability 
affects you, it may be prudent to retrieve the advisory from the canonical site 
to ensure that you receive the most current information concerning that problem.

Reference to any specific commercial product, process, or service by trade 
name, trademark manufacturer, or otherwise, does not constitute or imply 
its endorsement, recommendation, or favouring by UNIRAS or NISCC.  The views 
and opinions of authors expressed within this notice shall not be used for 
advertising or product endorsement purposes.

Neither UNIRAS or NISCC shall also accept responsibility for any errors 
or omissions contained within this briefing notice. In particular, they shall 
not be liable for any loss or damage whatsoever, arising from or in connection 
with the usage of information contained within this notice.

UNIRAS is a member of the Forum of Incident Response and Security Teams (FIRST) 
and has contacts with other international Incident Response Teams (IRTs) in 
order to foster cooperation and coordination in incident prevention, to prompt 
rapid reaction to incidents, and to promote information sharing amongst its 
members and the community at large. 
- ----------------------------------------------------------------------------------
<End of UNIRAS Briefing>

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.0

iQCVAwUBQwX4fopao72zK539AQGe2QP/VkPZGmELnb5FqrbbX4VVbQd5V+pZVUt9
RBgRTIgDch4+LpwoUYH4EJeZJQ6+BKxSyWnjyrygLrcNEjJXFrpUgx9RQnbfxUqK
hGkEoHzOFaKHbqjJ+lTmhJQXQfj5XzBeR4lYT5EXEJX83TD0VnFVOM/LDFrkFHUK
InCSNeV2SRs=
=w9cj
-----END PGP SIGNATURE-----


______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________

______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________