MGASA-2017-0267
Dashboard / Vulnerabilities / MGASA-2017-0267
MGASA-2017-0267
Summary: Updated cacti packages fix security vulnerabilities
Details: Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php (CVE-2017-10970). Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable (CVE-2017-11163). A Cross-site scripting vulnerability exists in cacti before 1.1.14 in the user profile managment page (auth_profile.php), allowing inject arbitrary web script or HTML via specially crafted HTTP Referer headers (CVE-2017-11691). spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter (CVE-2017-12065). Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable (CVE-2017-12066).
References: https://advisories.mageia.org/MGASA-2017-0267.html, https://bugs.mageia.org/show_bug.cgi?id=21242, https://www.cacti.net/changelog.php, https://lists.fedoraproject.org/archives/list/[email protected]/thread/7MRJCGVNDLW7RCTYSL72XGP74PCMOIH2/, http://openwall.com/lists/oss-security/2017/07/27/1, https://lists.fedoraproject.org/archives/list/[email protected]/thread/QN75M6HGIKEEX7HYFWHIO6IYDB5RXFP6/, https://lists.opensuse.org/opensuse-updates/2017-08/msg00018.html
Affected packages
Package
Name: cacti
Purl: pkg:rpm/mageia/cacti?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
