UbuntuUpdates.org

Package "cacti"

Name: cacti

Description:

web interface for graphing of monitoring systems

Latest version: 0.8.8f+ds1-4ubuntu4.16.04.2
Release: xenial (16.04)
Level: security
Repository: universe
Homepage: http://www.cacti.net/

Links


Download "cacti"


Other versions of "cacti" in Xenial

Repository Area Version
base universe 0.8.8f+ds1-4ubuntu4
updates universe 0.8.8f+ds1-4ubuntu4.16.04.2

Changelog

Version: 0.8.8f+ds1-4ubuntu4.16.04.2 2017-02-15 02:06:51 UTC

  cacti (0.8.8f+ds1-4ubuntu4.16.04.2) xenial-security; urgency=medium

  * Security update (backport patches from upstream)
    - CVE-2016-2313 - auth_login.php access restrictions could be bypassed
    - CVE-2016-3172 - SQL injection vulnerability in tree.php
    - CVE-2016-3659 - SQL injection vulnerability in graph_view.php

 -- Paul Gevers <email address hidden> Sat, 11 Feb 2017 14:07:55 +0100

CVE-2016-2313 auth_login.php in Cacti before 0.8.8g allows remote authenticated users who use web authentication to bypass intended access restrictions by logging
CVE-2016-3172 SQL injection vulnerability in tree.php in Cacti 0.8.8g and earlier allows remote authenticated users to execute arbitrary SQL commands via the paren
CVE-2016-3659 SQL injection vulnerability in graph_view.php in Cacti 0.8.8.g allows remote authenticated users to execute arbitrary SQL commands via the host_group



About   -   Send Feedback to @ubuntu_updates