First published: Mon Feb 10 2014(Updated: )
SQL injection issues were discovered in MantisBT, an open source issue tracker. <a href="https://access.redhat.com/security/cve/CVE-2014-1608">CVE-2014-1608</a> patch: <a href="https://github.com/mantisbt/mantisbt/commit/00b4c17088fa56594d85fe46b6c6057bb3421102">https://github.com/mantisbt/mantisbt/commit/00b4c17088fa56594d85fe46b6c6057bb3421102</a> <a href="https://access.redhat.com/security/cve/CVE-2014-1609">CVE-2014-1609</a> patch: <a href="https://github.com/mantisbt/mantisbt/commit/7efe0175f0853e18ebfacedfd2374c4179028b3f">https://github.com/mantisbt/mantisbt/commit/7efe0175f0853e18ebfacedfd2374c4179028b3f</a> It was reported that versions 1.1.0a4 to 1.2.15 are affected. References: <a href="http://www.ocert.org/advisories/ocert-2014-001.html">http://www.ocert.org/advisories/ocert-2014-001.html</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CentOS Libreport-plugin-mantisbt | <=1.2.15 | |
CentOS Libreport-plugin-mantisbt | =1.2.0 | |
CentOS Libreport-plugin-mantisbt | =1.2.0-alpha1 | |
CentOS Libreport-plugin-mantisbt | =1.2.0-alpha2 | |
CentOS Libreport-plugin-mantisbt | =1.2.0-alpha3 | |
CentOS Libreport-plugin-mantisbt | =1.2.0-rc1 | |
CentOS Libreport-plugin-mantisbt | =1.2.0-rc2 | |
CentOS Libreport-plugin-mantisbt | =1.2.1 | |
CentOS Libreport-plugin-mantisbt | =1.2.2 | |
CentOS Libreport-plugin-mantisbt | =1.2.3 | |
CentOS Libreport-plugin-mantisbt | =1.2.4 | |
CentOS Libreport-plugin-mantisbt | =1.2.5 | |
CentOS Libreport-plugin-mantisbt | =1.2.6 | |
CentOS Libreport-plugin-mantisbt | =1.2.7 | |
CentOS Libreport-plugin-mantisbt | =1.2.8 | |
CentOS Libreport-plugin-mantisbt | =1.2.9 | |
CentOS Libreport-plugin-mantisbt | =1.2.10 | |
CentOS Libreport-plugin-mantisbt | =1.2.11 | |
CentOS Libreport-plugin-mantisbt | =1.2.13 | |
CentOS Libreport-plugin-mantisbt | =1.2.14 | |
Debian Linux | =7.0 | |
<=1.2.15 | ||
=1.2.0 | ||
=1.2.0-alpha1 | ||
=1.2.0-alpha2 | ||
=1.2.0-alpha3 | ||
=1.2.0-rc1 | ||
=1.2.0-rc2 | ||
=1.2.1 | ||
=1.2.2 | ||
=1.2.3 | ||
=1.2.4 | ||
=1.2.5 | ||
=1.2.6 | ||
=1.2.7 | ||
=1.2.8 | ||
=1.2.9 | ||
=1.2.10 | ||
=1.2.11 | ||
=1.2.13 | ||
=1.2.14 | ||
=7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1608 is classified as a medium severity vulnerability due to SQL injection risks.
To fix CVE-2014-1608, upgrade MantisBT to the latest version that addresses the vulnerability.
CVE-2014-1608 affects MantisBT versions up to 1.2.15, including several earlier releases.
CVE-2014-1608 can allow attackers to execute arbitrary SQL commands, potentially compromising the database.
Yes, a patch for CVE-2014-1608 has been released and is available in the latest version of MantisBT.