Alerts This Week
Warning Icon 1 975
Alerts This Week
Warning Icon 1 975

Fedora 39 FEDORA-2024-27a594f71d Critical: Cacti Remote Code Execution

fedora
Calendar Grey May 31, 2024
Dist Fedora Esm H88
Essential revisions for the cacti utility encompass numerous upstream rectifications, tackling remote execution vulnerabilities and additional enhancements.
Update cacti and cacti-spine to version 1.2.27

Summary

Cacti is a complete frontend to RRDTool. It stores all of the

necessary information to create graphs and populate them with

data in a MySQL database. The frontend is completely PHP

driven.

Update Information:

Update cacti and cacti-spine to version 1.2.27. This includes the upstream fixes for many CVEs, including a critical remote code execution bug. https://github.com/Cacti/cacti/blob/release/1.2.27/CHANGELOG https://github.com/Cacti/spine/blob/release/1.2.27/CHANGELOG

Change Log

* Tue May 21 2024 Carl George - 1.2.27-1 - Update to version 1.2.27 - CVE-2024-25641, CVE-2024-29894, CVE-2024-31443, CVE-2024-31444, CVE-2024-31445, CVE-2024-31458, CVE-2024-31459, CVE-2024-31460, CVE-2024-34340 * Tue May 21 2024 Carl George - 1.2.26-1 - Update to version 1.2.26 - CVE-2023-49084, CVE-2023-49085, CVE-2023-49086, CVE-2023-49088, CVE-2023-50250, CVE-2023-51448

References


[ 1 ] Bug #2255602 - CVE-2023-49084 cacti: RCE when managing links [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255602 [ 2 ] Bug #2255606 - CVE-2023-49086 cacti: XSS when adding new devices [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255606 [ 3 ] Bug #2255667 - CVE-2023-49085 CVE-2023-49088 CVE-2023-50250 CVE-2023-51448 cacti: Multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2255667 [ 4 ] Bug #2280482 - CVE-2024-34340 cacti: authentication bypass when using older password hashes [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2280482 [ 5 ] Bug #2280497 - CVE-2024-29894 cacti: XSS vulnerability when using JavaScript based messaging API [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2280497 [ 6 ] Bug #2280500 - CVE-2024-31458 CVE-2024-31459 CVE-2024-31460 cacti: multiple vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.c...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-27a594f71d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: cacti
Product: Fedora 39
Version: 1.2.27
Release: 1.fc39
URL:
Summary: An rrd based graphing tool

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here