FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2012-2692

This CVE name corresponds to:

Entered Topic
2012-06-12 mantis -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2012-2692
Phase Assigned(20120514)

Description

MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when form_security_validation is set to OFF, which allows remote authenticated users with certain privileges to bypass intended access restrictions and delete arbitrary attachments.

References

Source Reference
MLIST [oss-security] 20120609 CVE requests (x2) for Mantis Bug Tracker (MantisBT) before 1.2.11
MLIST [oss-security] 20120611 Re: CVE requests (x2) for Mantis Bug Tracker (MantisBT) before 1.2.11
CONFIRM http://www.mantisbt.org/bugs/changelog_page.php?version_id=148
CONFIRM http://www.mantisbt.org/bugs/view.php?id=14016
CONFIRM https://github.com/mantisbt/mantisbt/commit/ceafe6f0c679411b81368052633a63dd3ca06d9c
FEDORA FEDORA-2012-18273
FEDORA FEDORA-2012-18294
FEDORA FEDORA-2012-18299
GENTOO GLSA-201211-01
BID 53921
SECUNIA 51199