FreeBSD Bugzilla – Attachment 157927 Details for
Bug 200963
[MAINTAINER] net-mgmt/cacti: Update to 0.8.8d, Fix security vulnerabilities
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
Remember
[x]
|
Forgot Password
Login:
[x]
[patch]
security/vuxml entry for cacti 0.8.8c and 0.8.8d multiple vulnerabilities
cacti-vuln-xml.diff (text/plain), 3.38 KB, created by
Jason Unovitch
on 2015-06-21 14:24:04 UTC
(
hide
)
Description:
security/vuxml entry for cacti 0.8.8c and 0.8.8d multiple vulnerabilities
Filename:
MIME Type:
Creator:
Jason Unovitch
Created:
2015-06-21 14:24:04 UTC
Size:
3.38 KB
patch
obsolete
>Index: vuln.xml >=================================================================== >--- vuln.xml (revision 390180) >+++ vuln.xml (working copy) >@@ -57,6 +57,92 @@ > > --> > <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> >+ <vuln vid="a3929112-181b-11e5-a1cf-002590263bf5"> >+ <topic>cacti -- Multiple XSS and SQL injection vulerabilities</topic> >+ <affects> >+ <package> >+ <name>cacti</name> >+ <range><lt>0.8.8d</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>The Cacti Group, Inc. reports:</p> >+ <blockquote cite="http://www.cacti.net/release_notes_0_8_8d.php"> >+ <p>Important Security Fixes</p> >+ <ul> >+ <li>Multiple XSS and SQL injection vulerabilities</li> >+ </ul> >+ <p>Changelog</p> >+ <ul> >+ <li>bug: Fixed SQL injection VN: JVN#78187936 / >+ TN:JPCERT#98968540</li> >+ <li>bug#0002542: [FG-VD-15-017] Cacti Cross-Site Scripting >+ Vulnerability Notification</li> >+ <li>bug#0002571: SQL Injection and Location header injection from >+ cdef id CVE-2015-4342</li> >+ <li>bug#0002572: SQL injection in graph template</li> >+ </ul> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <cvename>CVE-2015-4342</cvename> >+ <freebsdpr>ports/200963</freebsdpr> >+ <url>http://www.cacti.net/release_notes_0_8_8d.php</url> >+ <mlist>http://seclists.org/fulldisclosure/2015/Jun/19</mlist> >+ </references> >+ <dates> >+ <discovery>2015-06-09</discovery> >+ <entry>2015-06-21</entry> >+ </dates> >+ </vuln> >+ >+ <vuln vid="a0e74731-181b-11e5-a1cf-002590263bf5"> >+ <topic>cacti -- multiple security vulnerabilities</topic> >+ <affects> >+ <package> >+ <name>cacti</name> >+ <range><lt>0.8.8c</lt></range> >+ </package> >+ </affects> >+ <description> >+ <body xmlns="http://www.w3.org/1999/xhtml"> >+ <p>The Cacti Group, Inc. reports:</p> >+ <blockquote cite="http://www.cacti.net/release_notes_0_8_8c.php"> >+ <p>Important Security Fixes</p> >+ <ul> >+ <li>CVE-2013-5588 - XSS issue via installer or device editing</li> >+ <li>CVE-2013-5589 - SQL injection vulnerability in device editing</li> >+ <li>CVE-2014-2326 - XSS issue via CDEF editing</li> >+ <li>CVE-2014-2327 - Cross-site request forgery (CSRF) vulnerability</li> >+ <li>CVE-2014-2328 - Remote Command Execution Vulnerability in graph export</li> >+ <li>CVE-2014-4002 - XSS issues in multiple files</li> >+ <li>CVE-2014-5025 - XSS issue via data source editing</li> >+ <li>CVE-2014-5026 - XSS issues in multiple files</li> >+ </ul> >+ </blockquote> >+ </body> >+ </description> >+ <references> >+ <cvename>CVE-2013-5588</cvename> >+ <cvename>CVE-2013-5589</cvename> >+ <cvename>CVE-2014-2326</cvename> >+ <cvename>CVE-2014-2327</cvename> >+ <cvename>CVE-2014-2328</cvename> >+ <cvename>CVE-2014-4002</cvename> >+ <cvename>CVE-2014-5025</cvename> >+ <cvename>CVE-2014-5026</cvename> >+ <freebsdpr>ports/198586</freebsdpr> >+ <mlist>http://sourceforge.net/p/cacti/mailman/message/33072838/</mlist> >+ <url>http://www.cacti.net/release_notes_0_8_8c.php</url> >+ </references> >+ <dates> >+ <discovery>2014-11-23</discovery> >+ <entry>2015-06-21</entry> >+ </dates> >+ </vuln> >+ > <vuln vid="968d1e74-1740-11e5-a643-40a8f0757fb4"> > <topic>p5-Dancer -- possible to abuse session cookie values</topic> > <affects>
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Diff
View Attachment As Raw
Actions:
View
|
Diff
Attachments on
bug 200963
:
157879
|
157921
|
157922
| 157927