Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian: DSA-1954-1 Critical: Cacti Input Sanitising Problems

debian
Calendar Grey December 16, 2009
Debian Logo
Debian Security Advisory DSA-1955-2 covers vulnerabilities found in phpMyAdmin, emphasizing the need for secure coding to mitigate risks.
Several vulnerabilities have been found in cacti, a frontend to rrdtool for monitoring systems and services

Summary

CVE-2007-3112, CVE-2007-3113

It was discovered that cacti is prone to a denial of service via the
graph_height, graph_width, graph_start and graph_end parameters.
This issue only affects the oldstable (etch) version of cacti.

CVE-2009-4032

It was discovered that cacti is prone to several cross-site scripting
attacks via different vectors.

CVE-2009-4112

It has been discovered that cacti allows authenticated administrator
users to gain access to the host system by executing arbitrary commands
via the "Data Input Method" for the "Linux - Get Memory Usage" setting.

There is no fix for this issue at this stage. Upstream will implement a
whitelist policy to only allow certain "safe" commands. For the moment,
we recommend that such access is only given to trusted users and that
the options "Data Input" and "User Administration" are otherwise
deactivated.


For the oldstable distribution (etch), these problems have been fixed in
version 0.8.6i-3.6.

For the stable distribution (lenny), this problem has been fix...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here