Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Debian: DSA-2739-1 Critical: SQL And Command Injection In Cacti

debian
Calendar Grey August 21, 2013
Debian Logo
Essential patch for Cacti resolves SQL and command injection flaws impacting various Debian versions.
Two security issues (SQL injection and command line injection via SNMP settings) were found in Cacti, a web interface for graphing of monitoring systems

Summary

Two security issues (SQL injection and command line injection via SNMP
settings) were found in Cacti, a web interface for graphing of monitoring
systems.

For the oldstable distribution (squeeze), these problems have been fixed in
version 0.8.7g-1+squeeze2.

For the stable distribution (wheezy), these problems have been fixed in
version 0.8.8a+dfsg-5+deb7u1.

For the unstable distribution (sid), these problems have been fixed in
version 0.8.8b+dfsg-2.

We recommend that you upgrade your cacti packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: cacti
CVE ID: CVE-2013-1434 CVE-2013-1435

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here