|
|
Log in / Subscribe / Register

mantis: database credentials leak

Package(s):mantis CVE #(s):
Created:August 10, 2009 Updated:August 12, 2009
Description:

From the Debian advisory:

It was discovered that the Debian Mantis package, a web based bug tracking system, installed the database credentials in a file with world-readable permissions onto the local filesystem. This allows local users to acquire the credentials used to control the Mantis database.

Alerts:
Debian DSA-1856-1 mantis 2009-08-08

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds