FreeBSD : mantis -- multiple vulnerabilities (55587adb-b49d-11e1-8df1-0004aca374af)

high Nessus Plugin ID 59466

Synopsis

The remote FreeBSD host is missing a security-related update.

Description

Mantis reports :

Roland Becker and Damien Regad (MantisBT developers) found that any user able to report issues via the SOAP interface could also modify any bugnotes (comments) created by other users. In a default/typical MantisBT installation, SOAP API is enabled and any user can sign up to report new issues. This vulnerability therefore impacts upon many public facing MantisBT installations.

Roland Becker (MantisBT developer) found that the delete_attachments_threshold permission was not being checked when a user attempted to delete an attachment from an issue. The more generic update_bug_threshold permission was being checked instead. MantisBT administrators may have been under the false impression that their configuration of the delete_attachments_threshold was successfully preventing unwanted users from deleting attachments.

Solution

Update the affected package.

See Also

https://www.openwall.com/lists/oss-security/2012/06/09/1

http://www.nessus.org/u?b86d0808

http://www.nessus.org/u?7278080a

Plugin Details

Severity: High

ID: 59466

File Name: freebsd_pkg_55587adbb49d11e18df10004aca374af.nasl

Version: 1.8

Type: local

Published: 6/13/2012

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:freebsd:freebsd:mantis, cpe:/o:freebsd:freebsd

Required KB Items: Host/local_checks_enabled, Host/FreeBSD/release, Host/FreeBSD/pkg_info

Patch Publication Date: 6/12/2012

Vulnerability Publication Date: 6/9/2012

Reference Information

CVE: CVE-2012-2691, CVE-2012-2692