First published: Tue Aug 03 2010(Updated: )
A flaw was found in the way that the Mantis BTS handled attachments and MIME types. A user could upload an HTML file renamed to a .gif and Mantis would calculate the actual MIME type of the file as text/html. A user tricked into thinking they were clicking a .gif attachment would instead have the full HTML file rendered in the browser, rather than having it treated as a downloadable file or displayed in plain text. References: <a href="http://www.mantisbt.org/bugs/view.php?id=11952">http://www.mantisbt.org/bugs/view.php?id=11952</a> <a href="http://www.mantisbt.org/blog/?p=113">http://www.mantisbt.org/blog/?p=113</a> This was corrected in upstream version 1.2.2 and affects current Fedora 12, 13, rawhide, and EPEL5.
Affected Software | Affected Version | How to fix |
---|---|---|
MantisBT | <1.2.2 | |
Fedora | ||
Fedora Project Fedora Release Rawhide | ||
Fedora EPEL5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability REDHAT-BUG-620992 is considered to have a moderate severity level.
To fix REDHAT-BUG-620992, update Mantis BT to the latest version that addresses this issue.
REDHAT-BUG-620992 may lead to users being tricked into executing malicious HTML files disguised as GIF attachments.
Mantis BT versions up to but not including 1.2.2 are affected by REDHAT-BUG-620992.
In addition to Mantis BT, REDHAT-BUG-620992 may also impact various versions of Fedora and Fedora EPEL5.