DSA-3007-1 cacti -- security update

Related Vulnerabilities: CVE-2014-5025   CVE-2014-5026   CVE-2014-5261   CVE-2014-5262  

Multiple security issues (cross-site scripting, missing input sanitising and SQL injection) have been discovered in Cacti, a web interface for graphing of monitoring systems. For the stable distribution (wheezy), these problems have been fixed in version 0.8.8a+dfsg-5+deb7u4. For the unstable distribution (sid), these problems have been fixed in version 0.8.8b+dfsg-8. We recommend that you upgrade your cacti packages.

Debian Security Advisory

DSA-3007-1 cacti -- security update

Date Reported:
20 Aug 2014
Affected Packages:
cacti
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-5025, CVE-2014-5026, CVE-2014-5261, CVE-2014-5262.
More information:

Multiple security issues (cross-site scripting, missing input sanitising and SQL injection) have been discovered in Cacti, a web interface for graphing of monitoring systems.

For the stable distribution (wheezy), these problems have been fixed in version 0.8.8a+dfsg-5+deb7u4.

For the unstable distribution (sid), these problems have been fixed in version 0.8.8b+dfsg-8.

We recommend that you upgrade your cacti packages.