First published: Thu Jun 07 2007(Updated: )
graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_start or (2) graph_end parameter, different vectors than CVE-2007-3113.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti | <=0.8.6i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3112 has a moderate severity rating due to its potential to cause denial of service via resource exhaustion.
To fix CVE-2007-3112, upgrade Cacti to a version later than 0.8.6i that addresses this vulnerability.
CVE-2007-3112 affects versions of Cacti up to and including 0.8.6i as known vulnerable software.
CVE-2007-3112 involves a denial of service attack that can be triggered by remote authenticated users.
CVE-2007-3112 is triggered by manipulating the graph_start or graph_end parameters to consume excessive CPU resources.