MantisBT: master-1.2.x 215968fa

Author Committer Branch Timestamp Parent
Paul Richards dregad master-1.2.x 2013-10-12 13:58 master-1.2.x ea27796c
Affected Issues  0017640: CVE-2014-6387: Null byte poisoning in LDAP authentication
 0017967: Reporting an issue gives: 'Invalid argument supplied for foreach()' in '/opt/mantisbt-1.2.18/core/gpc_api.php' line 259
 0017977: Fix handling of due dates
Changeset

Strip null bytes out of GPC input strings

Backporting commit fc02c46eea9d9e7cc472a7fc1801ea65d467db76 from master
branch to fix issue 0017640

Signed-off-by: Damien Regad dregad@mantisbt.org

mod - core/gpc_api.php Diff File