Summary
The remote host is missing an update to mantis
announced via advisory DSA 161-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%20161-1
Insight
A problem with user privileges has been discovered in the Mantis package, a PHP based bug tracking system. The Mantis system didn't check whether a user is permitted to view a bug, but displays it right away if the user entered a valid bug id.
Another bug in Mantis caused the 'View Bugs' page to list bugs from both public and private projects when no projects are accessible to the current user.
These problems have been fixed in version 0.17.1-2.5 for the current stable distribution (woody) and in version 0.17.5-2 for the unstable distribution (sid). The old stable distribution (potato) is not affected, since it doesn't contain the mantis package.
We recommend that you upgrade your mantis packages.
Severity
Classification
-
CVE CVE-2002-1115, CVE-2002-1116 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities