Debian Linux Security Advisory 3007-1 - Multiple security issues (cross-site scripting, missing input sanitising and SQL injection) have been discovered in Cacti, a web interface for graphing of monitoring systems.
4f0e774ab42a6d70a94103e9e8f16df9a32a25d26c01b1a17ccf40a3b0bdc588
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- -------------------------------------------------------------------------
Debian Security Advisory DSA-3007-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 20, 2014 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : cacti
CVE ID : CVE-2014-5025 CVE-2014-5026 CVE-2014-5027 CVE-2014-5261
CVE-2014-5262
Multiple security issues (cross-site scripting, missing input sanitising
and SQL injection) have been discovered in Cacti, a web interface for
graphing of monitoring systems.
For the stable distribution (wheezy), these problems have been fixed in
version 0.8.8a+dfsg-5+deb7u4.
For the unstable distribution (sid), these problems have been fixed in
version 0.8.8b+dfsg-8.
We recommend that you upgrade your cacti packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBAgAGBQJT9HFcAAoJEBDCk7bDfE42s/4P/0UZ/QIdagDeELhisrRLSihv
uM9CmWPJBwIrYXkNB7zGZrCidVT6LBG+JbkYUBOGVeylhJYJNrEqbAN4H8DBe/vd
lgC8PGbkxqrhPjEGXDvnE4sTK8D+1LldiDWq352PFI6AwxURmJ1KnasF7ulbLKjC
oCJv5Rf481pqZ8zbSu1UW34KHTJX/LUzLKaMto91BaOPs3Js8wsdgqGpEgQJ33Uk
PlEWo1ktBEk9CfDnm6l7gKHIhr/NNk3Eg4hH2q/Vt/QB6NBLvBaUGz7Jqq0sL3A4
KudJT1KqWDt5ke7woaeb8zyFUbvP3lYUJnQlY65iYZFbiQ7KGRH8p54OfxTLZo1L
TuOMKrRp+iMFbV/mCcBSXBUZhSvqcpk5hcUgxuVZPST1bcfOiPor9aK1YHYR6Msr
Gx5ogRcdVu1f5NfpT57CySY5/DojptAQagTNvg63gYyuBiVvVRWQxzpRqDhavTdb
5EPiBwEmMNdCmZh7MarxCaAaUU+JdrmUxCFZmVh7EIYbdmK6WupgL4ibsL35fRPx
Tlj12ZWs7Tpw4rlfevOxwUl9aKH894DJVmlbqthgforjcIm+fHCcS0VWKvJCCo3s
QAv8TC61IF80jtf1xsi6Ja8uf+w/U7lWFMZ+QYp68lQPgPOSo5X1Bk49PDPBIW79
r3dyGOKWOKH7u773xVe6
=mLle
-----END PGP SIGNATURE-----