cacti 1.2.2+ds1-2+deb10u3 source package in Debian

Changelog

cacti (1.2.2+ds1-2+deb10u3) buster; urgency=medium

  * Unix timestamps after Sep 13 2020 are rejected as graph start/end
    arguments (Upstream bug #3245)
  * CVE-2020-7237: Remote Code Execution (by privileged users) via shell
    metacharacters in the Performance Boost Debug Log field of
    poller_automation.php. OS commands are executed when a new poller
    cycle begins. The attacker must be authenticated, and must have access
    to modify the Performance Settings of the product. (Closes: #949997)
  * CVE-2020-7106: XSS in data_sources.php, color_templates_item.php,
    graphs.php, graph_items.php, lib/api_automation.php, user_admin.php,
    and user_group_admin.php, as demonstrated by the description parameter
    in data_sources.php (a raw string from the database that is displayed
    by $header to trigger the XSS). (Closes: #949996)
  * CVE-2020-13230: Disabling an user account does not immediately
    invalidate any permissions granted to that account (e.g., permission
    to view logs)
  * CVE-2020-13231: auth_profile.php?action=edit allows CSRF for an admin
    email change

 -- Paul Gevers <email address hidden>  Thu, 18 Jun 2020 22:34:41 +0200

Upload details

Uploaded by:
Cacti Maintainer
Uploaded to:
Buster
Original maintainer:
Cacti Maintainer
Architectures:
all
Section:
web
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Builds

Downloads

File Size SHA-256 Checksum
cacti_1.2.2+ds1-2+deb10u3.dsc 2.2 KiB b9b4889ddd6c1ca37f9f89ae53f82a19f4178cde1b4a85a439486a311d5b47cf
cacti_1.2.2+ds1.orig-docs-source.tar.gz 12.2 MiB 5d94359ea0b15cfe8f96ddc9999394594563cb34de2bb500a54f7b27565b44b4
cacti_1.2.2+ds1.orig.tar.xz 3.5 MiB 45d263e2cbc7aa40e162c35adbe45229bd231e16faf082dbc01fb36403140bef
cacti_1.2.2+ds1-2+deb10u3.debian.tar.xz 64.6 KiB fdea59cd06101307c0f338b0c18e4db11831118a6d6c23db28fe2358b9142c52

No changes file available.

Binary packages built by this source