---------------------------------------------------------------------- Do you have VARM strategy implemented? (Vulnerability Assessment Remediation Management) If not, then implement it through the most reliable vulnerability intelligence source on the market. Implement it through Secunia. For more information visit: http://secunia.com/advisories/business_solutions/ Alternatively request a call from a Secunia representative today to discuss how we can help you with our capabilities contact us at: sales@secunia.com ---------------------------------------------------------------------- TITLE: Debian update for mantis SECUNIA ADVISORY ID: SA36225 VERIFY ADVISORY: http://secunia.com/advisories/36225/ DESCRIPTION: Debian has issued an update for mantis. This fixes a security issue, which can be exploited by malicious, local users to disclose sensitive information. The security issue is caused due to insecure permissions being set for /etc/mantis/config_db.php, which can be exploited to disclose the credentials for the mantis database. SOLUTION: Apply updated packages. -- Debian GNU/Linux 5.0 alias lenny -- Source archives: http://security.debian.org/pool/updates/main/m/mantis/mantis_1.1.6+dfsg.orig.tar.gz Size/MD5 checksum: 2044082 429853b8caacc9e713b686524524418a http://security.debian.org/pool/updates/main/m/mantis/mantis_1.1.6+dfsg-2lenny1.dsc Size/MD5 checksum: 1208 f77403f035efa94936500520fe273692 http://security.debian.org/pool/updates/main/m/mantis/mantis_1.1.6+dfsg-2lenny1.diff.gz Size/MD5 checksum: 45118 68a32687bce135f3032a184c8ebf788f Architecture independent packages: http://security.debian.org/pool/updates/main/m/mantis/mantis_1.1.6+dfsg-2lenny1_all.deb Size/MD5 checksum: 1744390 7a7ff3cd017be50fa3ba162ac82eb3de PROVIDED AND/OR DISCOVERED BY: Reported by Cyril Bouthors in a Debian bug report. ORIGINAL ADVISORY: DSA-1856-1: http://www.us.debian.org/security/2009/dsa-1856 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=425010 ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------