CVE-2007-3113: Medium severity The Cacti Group Cacti vulnerability
Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graphheight or (2) graphwidth parameter, different vectors than CVE-2007-3112.
Other sources
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-3112 "Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graphstart or (2) graphend parameter."
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-3113 "Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graphheight or (2) graphwidth parameter."
The patch linked to in the reports applies to 0.8.6j too.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3113?
CVE-2007-3113 has a high severity due to its potential to cause denial of service by consuming excessive CPU resources.
How do I fix CVE-2007-3113?
To fix CVE-2007-3113, upgrade Cacti to version 0.8.6j or later.
What versions of Cacti are affected by CVE-2007-3113?
CVE-2007-3113 affects Cacti version 0.8.6i and possibly earlier versions.
Can CVE-2007-3113 be exploited by unauthenticated users?
No, CVE-2007-3113 can only be exploited by remote authenticated users.
What is the impact of an attack exploiting CVE-2007-3113?
An attack exploiting CVE-2007-3113 can lead to significant CPU consumption, resulting in a denial of service.