OSVDB ID: 22056

Title: Mantis File Size Upload Restriction Bypass DoS

Info

Disclosure

Dec 23, 2005

Discovery

Nov 04, 2005

Dates

Exploit

Dec 23, 2005

Solution

Unknown

Description

Mantis contains a flaw that may allow a remote denial of service. The issue is triggered when a remote atacker passes a unusually large value to the 'max_file_size' variable which is not properly sanitized in the bug_file_add.php, bug_report.php, bug_report_advanced_page.php and proj_doc_add_page.php scripts allowing the uploaded file to fill the available disk space for the database and will result in loss of availability for the service.

Classification

Location: Remote / Network Access
Attack Type: Denial of Service
Impact: Loss of Availability
Exploit: Exploit Public
Disclosure: OSVDB Verified

Solution

Upgrade to version 0.19.4, 1.0.0rc4 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Mantis

Mantis

0.19.3
1.0.0rc3

References

Credit

  • Tobias Klein - tktrapkit.de -


Direct URL: http://osvdb.org/36218