CVE-2010-4349

Publication date 3 January 2011

Last updated 24 July 2024


Ubuntu priority

Description

admin/upgrade_unattended.php in MantisBT before 1.2.4 allows remote attackers to obtain sensitive information via an invalid db_type parameter, which reveals the installation path in an error message, related to an unsafe call by MantisBT to a function in the ADOdb Library for PHP.

Status

Package Ubuntu Release Status
mantis 10.10 maverick
Not affected
10.04 LTS lucid
Not affected
9.10 karmic
Not affected
8.04 LTS hardy
Not affected
6.06 LTS dapper
Not affected


Access our resources on patching vulnerabilities