Title: Mantis File Size Upload Restriction Bypass DoS
Info
Disclosure
Dec 23, 2005
Discovery
Nov 04, 2005
Dates
Exploit
Dec 23, 2005
Solution
Unknown
Description
Mantis contains a flaw that may allow a remote denial of service. The issue is triggered when a remote atacker passes a unusually large value to the 'max_file_size' variable which is not properly sanitized in the bug_file_add.php, bug_report.php, bug_report_advanced_page.php and proj_doc_add_page.php scripts allowing the uploaded file to fill the available disk space for the database and will result in loss of availability for the service.
Classification
Location:
Remote / Network Access
Attack Type:
Denial of Service
Impact:
Loss of Availability
Exploit:
Exploit Public
Disclosure:
OSVDB Verified,
Vendor Verified
Solution
Upgrade to version 0.19.4, 1.0.0rc4 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.