Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Debian: DSA-3007-1 Critical: Cacti SQL Injection and XSS Issues

debian
Calendar Grey August 20, 2014
Scroller Debian
Cacti, an open-source network monitoring tool, faces serious security issues, especially on Debian, mainly due to improper input sanitization and SQL injection targets.
Multiple security issues (cross-site scripting, missing input sanitising and SQL injection) have been discovered in Cacti, a web interface for graphing of monitoring systems

Summary

Multiple security issues (cross-site scripting, missing input sanitising
and SQL injection) have been discovered in Cacti, a web interface for
graphing of monitoring systems.

For the stable distribution (wheezy), these problems have been fixed in
version 0.8.8a+dfsg-5+deb7u4.

For the unstable distribution (sid), these problems have been fixed in
version 0.8.8b+dfsg-8.

We recommend that you upgrade your cacti packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: cacti
CVE ID: CVE-2014-5025 CVE-2014-5026 CVE-2014-5027 CVE-2014-5261

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.