CVE-2014-6387: Medium severity centos libreport-plugin-mantisbt vulnerability
Published Oct 22, 2014
·Updated
gpcapi.php in MantisBT 1.2.17 and earlier allows remote attackers to bypass authenticated via a password starting will a null byte, which triggers an unauthenticated bind.
Affected Software
23 affected components
MantisBT mantisbt<=1.2.17
MantisBT mantisbt=1.2.0
MantisBT mantisbt=1.2.0-alpha1
MantisBT mantisbt=1.2.0-alpha2
MantisBT mantisbt=1.2.0-alpha3
MantisBT mantisbt=1.2.0-rc1
MantisBT mantisbt=1.2.0-rc2
MantisBT mantisbt=1.2.1
MantisBT mantisbt=1.2.2
MantisBT mantisbt=1.2.3
MantisBT mantisbt=1.2.4
MantisBT mantisbt=1.2.5
MantisBT mantisbt=1.2.6
MantisBT mantisbt=1.2.7
MantisBT mantisbt=1.2.8
MantisBT mantisbt=1.2.9
MantisBT mantisbt=1.2.10
MantisBT mantisbt=1.2.11
MantisBT mantisbt=1.2.12
MantisBT mantisbt=1.2.13
MantisBT mantisbt=1.2.14
MantisBT mantisbt=1.2.15
MantisBT mantisbt=1.2.16
Event History
Oct 22, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6387?
CVE-2014-6387 has been classified as a high severity vulnerability due to its ability to allow unauthenticated access to the system.
2
How do I fix CVE-2014-6387?
To fix CVE-2014-6387, upgrade MantisBT to version 1.2.18 or later where this vulnerability has been addressed.
3
Which versions are affected by CVE-2014-6387?
CVE-2014-6387 affects MantisBT versions up to and including 1.2.17.
4
What type of vulnerability is CVE-2014-6387?
CVE-2014-6387 is a remote code execution vulnerability that allows attackers to bypass authentication.
5
Can I exploit CVE-2014-6387 without authentication?
Yes, CVE-2014-6387 can be exploited by attackers without requiring authentication due to the null byte password bypass.