CVE-2014-1609
published 2014-03-20CVE-2014-1609: Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1)…
PriorityP347high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.07%
86.1th percentile
Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1) mc_project_get_attachments function in api/soap/mc_project_api.php; the (2) news_get_limited_rows function in core/news_api.php; the (3) summary_print_by_enum, (4) summary_print_by_age, (5) summary_print_by_developer, (6) summary_print_by_reporter, or (7) summary_print_by_category function in core/summary_api.php; the (8) create_bug_enum_summary or (9) enum_bug_group function in plugins/MantisGraph/core/graph_api.php; (10) bug_graph_bycategory.php or (11) bug_graph_bystatus.php in plugins/MantisGraph/pages/; or (12) proj_doc_page.php, related to use of the db_query function, a different vulnerability than CVE-2014-1608.
Affected
54 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| mantisbt | mantisbt | <= 1.2.17 | — |
| mantisbt | mantisbt | <= 1.2.15 | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
| mantisbt | mantisbt | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
cisa5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4pj9-mpj4-ccm8: Multiple SQL injection vulnerabilities in MantisBT before 1
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2014-1609 [HIGH] CWE-89 GHSA-4pj9-mpj4-ccm8: Multiple SQL injection vulnerabilities in MantisBT before 1
Multiple SQL injection vulnerabilities in MantisBT before 1.2.16 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to the (1) mc_project_get_attachments function in api/soap/mc_project_api.php; the (2) news_get_limited_rows function in core/news_api.php; the (3) summary_print_by_enum, (4) summary_print_by_age, (5) summary_print_by_developer, (6) summary_print_by_reporter, or (7) summary_print_by_category function in core/summary_api.php; the (8) create_bug_enum_summary or (9) enum_bug_group function in plugins/MantisGraph/core/graph_api.php; (10) bug_graph_bycategory.php or (11) bug_graph_bystatus.php in plugins/MantisGraph/pages/; or (12) proj_doc_page.php, related to use of the db_query function, a different vulnerability than CVE-2014-1608.
GHSA
GHSA-56cx-256p-gj3x: SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2014-8554 [HIGH] CWE-89 GHSA-56cx-256p-gj3x: SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api
SQL injection vulnerability in the mc_project_get_attachments function in api/soap/mc_project_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary SQL commands via the project_id parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1609.
CISA
Linux Kernel Race Condition Vulnerability
cisa·2023-05-12·CVSS 5.5
CVE-2014-0196 [MEDIUM] CWE-362 Linux Kernel Race Condition Vulnerability
Vulnerability: Linux Kernel Race Condition Vulnerability
Affected: Linux Kernel
Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings.
Required Action: The impacted product is end-of-life and should be disconnected if still in use.
Notes: https://lkml.iu.edu/hypermail/linux/kernel/1609.1/02103.html; https://nvd.nist.gov/vuln/detail/CVE-2014-0196
Remediation Due Date: 2023-06-02
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8554 mantis: incomplete fix for CVE-2014-1609 [fedora-all]
bugzilla·2014-11-03·CVSS 7.5
CVE-2014-8554 [HIGH] CVE-2014-8554 mantis: incomplete fix for CVE-2014-1609 [fedora-all]
CVE-2014-8554 mantis: incomplete fix for CVE-2014-1609 [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Wh
Bugzilla
CVE-2014-8554 mantis: incomplete fix for CVE-2014-1609 [epel-5]
bugzilla·2014-11-03·CVSS 7.5
CVE-2014-8554 [HIGH] CVE-2014-8554 mantis: incomplete fix for CVE-2014-1609 [epel-5]
CVE-2014-8554 mantis: incomplete fix for CVE-2014-1609 [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-5 tracking bug for mantis: see blocks bug list for full deta
Bugzilla
CVE-2014-8554 mantis: incomplete fix for CVE-2014-1609
bugzilla·2014-10-31·CVSS 7.5
CVE-2014-8554 [HIGH] CVE-2014-8554 mantis: incomplete fix for CVE-2014-1609
CVE-2014-8554 mantis: incomplete fix for CVE-2014-1609
It was reported [1] that fix for CVE-2014-1609 for MantisBT is not complete.
It was discovered that the patch did not fully address the original problem in the SOAP API.
Research demonstrates that using a specially crafted 'project id' parameter when calling
mc_project_get_attachments(), an attacker could still perform an SQL injection.
[1]: http://seclists.org/oss-sec/2014/q4/478
Discussion:
Created mantis tracking bugs for this issue:
Affects: fedora-all [bug 1159679]
Affects: epel-5 [bug 1159680]
---
mantis-1.2.17-4.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
---
mantis-1.2.17-4.fc21 has been pushed to the Fedora 21 stable repository. If prob
Bugzilla
CVE-2014-1608 CVE-2014-1609 mantis: SQL injection issues
bugzilla·2014-02-10·CVSS 7.5
CVE-2014-1608 [HIGH] CVE-2014-1608 CVE-2014-1609 mantis: SQL injection issues
CVE-2014-1608 CVE-2014-1609 mantis: SQL injection issues
SQL injection issues were discovered in MantisBT, an open source issue tracker.
CVE-2014-1608 patch:
https://github.com/mantisbt/mantisbt/commit/00b4c17088fa56594d85fe46b6c6057bb3421102
CVE-2014-1609 patch:
https://github.com/mantisbt/mantisbt/commit/7efe0175f0853e18ebfacedfd2374c4179028b3f
It was reported that versions 1.1.0a4 to 1.2.15 are affected.
References:
http://www.ocert.org/advisories/ocert-2014-001.html
Discussion:
Created mantis tracking bugs for this issue:
Affects: fedora-all [bug 1063113]
Affects: epel-5 [bug 1063114]
---
mantis-1.2.17-1.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
---
mantis-1.2.17-1.fc20 has been pushed to t
Bugzilla
CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [fedora-all]
bugzilla·2014-02-10·CVSS 7.5
CVE-2014-1609 [HIGH] CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [fedora-all]
CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects mul
Bugzilla
CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [epel-5]
bugzilla·2014-02-10·CVSS 7.5
CVE-2014-1609 [HIGH] CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [epel-5]
CVE-2014-1609 CVE-2014-1608 mantis: SQL injection issues [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tracking bug for mantis: se
http://secunia.com/advisories/61432http://www.debian.org/security/2014/dsa-3030http://www.mantisbt.org/bugs/view.php?id=16880http://www.ocert.org/advisories/ocert-2014-001.htmlhttp://www.securityfocus.com/bid/65461https://bugzilla.redhat.com/show_bug.cgi?id=1063111https://github.com/mantisbt/mantisbt/commit/7efe0175f0853e18ebfacedfd2374c4179028b3fhttp://secunia.com/advisories/61432http://www.debian.org/security/2014/dsa-3030http://www.mantisbt.org/bugs/view.php?id=16880http://www.ocert.org/advisories/ocert-2014-001.htmlhttp://www.securityfocus.com/bid/65461https://bugzilla.redhat.com/show_bug.cgi?id=1063111https://github.com/mantisbt/mantisbt/commit/7efe0175f0853e18ebfacedfd2374c4179028b3f
2014-03-20
Published