REDHAT-BUG-620992: Medium severity MantisBT Mantis BT vulnerability
A flaw was found in the way that the Mantis BTS handled attachments and MIME types. A user could upload an HTML file renamed to a .gif and Mantis would calculate the actual MIME type of the file as text/html. A user tricked into thinking they were clicking a .gif attachment would instead have the full HTML file rendered in the browser, rather than having it treated as a downloadable file or displayed in plain text.
References:
http://www.mantisbt.org/bugs/view.php?id=11952 http://www.mantisbt.org/blog/?p=113
This was corrected in upstream version 1.2.2 and affects current Fedora 12, 13, rawhide, and EPEL5.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-620992?
The vulnerability REDHAT-BUG-620992 is considered to have a moderate severity level.
How do I fix REDHAT-BUG-620992?
To fix REDHAT-BUG-620992, update Mantis BT to the latest version that addresses this issue.
What are the potential impacts of REDHAT-BUG-620992?
REDHAT-BUG-620992 may lead to users being tricked into executing malicious HTML files disguised as GIF attachments.
Which versions of Mantis BT are affected by REDHAT-BUG-620992?
Mantis BT versions up to but not including 1.2.2 are affected by REDHAT-BUG-620992.
What other software does REDHAT-BUG-620992 affect?
In addition to Mantis BT, REDHAT-BUG-620992 may also impact various versions of Fedora and Fedora EPEL5.