oss-sec mailing list archives
Re: CVE Request -- Cacti v0.8.7 -- three security fixes
From: "Steven M. Christey" <coley () linus mitre org>
Date: Mon, 7 Jun 2010 10:21:33 -0400 (EDT)
On Tue, 1 Jun 2010, Jan Lieskovsky wrote:
[C], SQL injection and shell escaping issues reported by Bonsai Information Security (http://www.bonsai-sec.com) [7] http://www.bonsai-sec.com/blog/index.php/using-grep-to-find-0days/ [8] http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-os-command-injection-0105.php...
2, OS command injection issue, CVE-2010-1645 / BONSAI-2010-0105References: [2] http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-os-command-injection-0105.php Proper patches are the following three: (noticed by Tomas Hoger && confirmed by Tony Roman, thanks for it!)[3] http://svn.cacti.net/viewvc?view=rev&revision=5778 [4] http://svn.cacti.net/viewvc?view=rev&revision=5782 [5] http://svn.cacti.net/viewvc?view=rev&revision=5784
The BONSAI-2010-0105 references two problems, one for ping.php and another one having to do with a "Vertical Label" in a "Graph Template."
I don't see evidence of this vector in the revisions listed above. Does anybody else?
(If the "Vertical Label" issue went unpatched, then a separate CVE should probably be assigned to it.)
- Steve
Current thread:
- CVE Request -- Cacti v0.8.7 -- three security fixes Jan Lieskovsky (May 24)
- Re: CVE Request -- Cacti v0.8.7 -- three security fixes Josh Bressers (May 26)
- Re: CVE Request -- Cacti v0.8.7 -- three security fixes Steven M. Christey (May 27)
- Re: CVE Request -- Cacti v0.8.7 -- three security fixes Jan Lieskovsky (Jun 01)
- Re: CVE Request -- Cacti v0.8.7 -- three security fixes Steven M. Christey (Jun 07)
- Re: CVE Request -- Cacti v0.8.7 -- three security fixes Larry Adams (Jun 07)
- Re: CVE Request -- Cacti v0.8.7 -- three security fixes Tony Roman (Jun 07)
- Re: CVE Request -- Cacti v0.8.7 -- three security fixes Steven M. Christey (May 27)
- Re: CVE Request -- Cacti v0.8.7 -- three security fixes Josh Bressers (May 26)
