First published: Fri Apr 04 2014(Updated: )
Cacti <a class="bz_bug_link bz_status_CLOSED bz_closed bz_public " title="CLOSED NOTABUG - mkbootdisk generates bad floppy" href="show_bug.cgi?id=2405">bug#0002405</a> includes fixes for SQL injection and shell escaping (which could lead to arbitrary command execution). Fixes are available from: <a href="http://svn.cacti.net/viewvc?view=rev&revision=7439">http://svn.cacti.net/viewvc?view=rev&revision=7439</a> <a href="https://access.redhat.com/security/cve/CVE-2014-2708">CVE-2014-2708</a> is for the SQL injection issues in graph_xport.php. <a href="https://access.redhat.com/security/cve/CVE-2014-2709">CVE-2014-2709</a> is for the shell escaping issues in lib/rrd.php References: <a href="http://seclists.org/oss-sec/2014/q2/15">http://seclists.org/oss-sec/2014/q2/15</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/cacti | 1.2.16+ds1-2+deb11u3 1.2.24+ds1-1+deb12u2 1.2.27+ds1-2 | |
Cacti | =0.8.8b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.