Title: Mantis File Size Upload Restriction Bypass DoS
Info
Disclosure
Dec 23, 2005
Discovery
Nov 04, 2005
Dates
Exploit
Dec 23, 2005
Solution
Unknown
Description
Mantis contains a flaw that may allow a remote denial of service. The issue is triggered when a remote atacker passes a unusually large value to the 'max_file_size' variable which is not properly sanitized in the bug_file_add.php, bug_report.php, bug_report_advanced_page.php and proj_doc_add_page.php scripts allowing the uploaded file to fill the available disk space for the database and will result in loss of availability for the service.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service
Impact:
Loss of Availability
Exploit:
Exploit Public
Disclosure:
OSVDB Verified
Solution
Upgrade to version 0.19.4, 1.0.0rc4 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.