GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sat Nov 11, 2017 8:26 pm Post subject: [ GLSA 201711-10 ] Cacti |
|
|
Gentoo Linux Security Advisory
Title: Cacti: Multiple vulnerabilities (GLSA 201711-10)
Severity: normal
Exploitable: remote
Date: 2017-11-11
Bug(s): #607732, #626828
ID: 201711-10
Synopsis
Multiple vulnerabilities have been found in Cacti, the worst of
which could lead to the remote execution of arbitrary code.
Background
Cacti is a complete frontend to rrdtool.
Affected Packages
Package: net-analyzer/cacti
Vulnerable: < 1.1.20
Unaffected: >= 1.1.20
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Cacti. Please review
the CVE identifiers referenced below for details.
Impact
Remote attackers could execute arbitrary code or bypass intended access
restrictions.
Workaround
There is no known workaround at this time.
Resolution
All Cacti users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=net-analyzer/cacti-1.1.20:1.1.20"
|
References
CVE-2014-4000
CVE-2016-2313
CVE-2017-12065
Last edited by GLSA on Mon Jan 15, 2018 4:17 am; edited 1 time in total |
|