CVE-2004-1731: Medium severity Mantis Mantis vulnerability
Published Aug 20, 2004
·Updated
signuppage.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providing the same e-mail address.
Affected Software
50 affected components
Mantis Mantis=0.10.2
Mantis Mantis=0.10
Mantis Mantis=0.14.7
Mantis Mantis=0.15.12
Mantis Mantis=0.18.0a2
Mantis Mantis=0.18.0a4
Mantis Mantis=0.15.3
Mantis Mantis=0.18
Mantis Mantis=0.15.9
Mantis Mantis=0.14.2
Mantis Mantis=0.9.1
Mantis Mantis=0.13
Mantis Mantis=0.10.1
Mantis Mantis=0.17.0
Mantis Mantis=0.15.10
Mantis Mantis=0.16.1
Mantis Mantis=0.15.2
Mantis Mantis=0.15.4
Mantis Mantis=0.15.11
Mantis Mantis=0.11
Mantis Mantis=0.17.4a
Mantis Mantis=0.14.5
Mantis Mantis=0.18.0a3
Mantis Mantis=0.17.2
Mantis Mantis=0.14.3
Mantis Mantis=0.15.7
Mantis Mantis=0.17.3
Mantis Mantis=0.17.1
Mantis Mantis=0.19.0a
Mantis Mantis=0.16
Mantis Mantis=0.18.0_rc1
Mantis Mantis=0.14.6
Mantis Mantis=0.14.4
Mantis Mantis=0.11.1
Mantis Mantis=0.15.5
Mantis Mantis=0.12
Mantis Mantis=0.15.1
Mantis Mantis=0.14.8
Mantis Mantis=0.17.5
Mantis Mantis=0.16.0
Mantis Mantis=0.18a1
Mantis Mantis=0.13.1
Mantis Mantis=0.15.8
Mantis Mantis=0.17.4
Mantis Mantis=0.14.1
Mantis Mantis=0.15.6
Mantis Mantis=0.17
Mantis Mantis=0.14
Mantis Mantis=0.15
Mantis Mantis=0.9
Remediation
Patch Available
Event History
Aug 20, 2004
CVE Published
04:00 AM
Feb 26, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1731?
CVE-2004-1731 is considered a moderate severity vulnerability due to its potential to allow email flooding.
2
How do I fix CVE-2004-1731?
To fix CVE-2004-1731, you should update the Mantis bugtracker to a version that includes a patch addressing this vulnerability.
3
What types of attacks can be executed using CVE-2004-1731?
CVE-2004-1731 allows remote attackers to execute denial-of-service attacks by sending excessive email messages to a single address.
4
Which versions of Mantis are affected by CVE-2004-1731?
CVE-2004-1731 affects multiple versions of Mantis, specifically versions prior to 0.19.0a.
5
Is there a workaround for CVE-2004-1731?
A temporary workaround for CVE-2004-1731 could be to limit the ability to create multiple accounts with the same email address.