Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.66592
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-1954-1)
Summary:The remote host is missing an update for the Debian 'cacti' package(s) announced via the DSA-1954-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'cacti' package(s) announced via the DSA-1954-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been found in cacti, a frontend to rrdtool for monitoring systems and services. The Common Vulnerabilities and Exposures project identifies the following problems:

CVE-2007-3112, CVE-2007-3113 It was discovered that cacti is prone to a denial of service via the graph_height, graph_width, graph_start and graph_end parameters. This issue only affects the oldstable (etch) version of cacti.

CVE-2009-4032

It was discovered that cacti is prone to several cross-site scripting attacks via different vectors.

CVE-2009-4112

It has been discovered that cacti allows authenticated administrator users to gain access to the host system by executing arbitrary commands via the 'Data Input Method' for the 'Linux - Get Memory Usage' setting.

There is no fix for this issue at this stage. Upstream will implement a whitelist policy to only allow certain 'safe' commands. For the moment, we recommend that such access is only given to trusted users and that the options 'Data Input' and 'User Administration' are otherwise deactivated.

For the oldstable distribution (etch), these problems have been fixed in version 0.8.6i-3.6.

For the stable distribution (lenny), this problem has been fixed in version 0.8.7b-2.1+lenny1.

For the testing distribution (squeeze), this problem will be fixed soon.

For the unstable distribution (sid), this problem has been fixed in version 0.8.7e-1.1.

We recommend that you upgrade your cacti packages.

Affected Software/OS:
'cacti' package(s) on Debian 4, Debian 5.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-3112
http://fedoranews.org/updates/FEDORA-2007-219.shtml
http://archives.neohapsis.com/archives/fulldisclosure/2007-06/0074.html
http://www.mandriva.com/security/advisories?name=MDKSA-2007:184
http://mdessus.free.fr/?p=15
https://bugzilla.redhat.com/show_bug.cgi?id=243592
http://osvdb.org/37019
http://secunia.com/advisories/25557
http://secunia.com/advisories/26872
XForce ISS Database: cacti-graphstart-graphend-dos(34747)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34747
Common Vulnerability Exposure (CVE) ID: CVE-2007-3113
Common Vulnerability Exposure (CVE) ID: CVE-2009-4032
20091125 Cacti 0.8.7e: Multiple security issues
http://archives.neohapsis.com/archives/fulldisclosure/2009-11/0292.html
20091126 Cacti 0.8.7e: Multiple security issues
http://www.securityfocus.com/archive/1/508129/100/0/threaded
37109
http://www.securityfocus.com/bid/37109
37481
http://secunia.com/advisories/37481
37934
http://secunia.com/advisories/37934
38087
http://secunia.com/advisories/38087
41041
http://secunia.com/advisories/41041
60483
http://www.osvdb.org/60483
ADV-2009-3325
http://www.vupen.com/english/advisories/2009/3325
ADV-2010-2132
http://www.vupen.com/english/advisories/2010/2132
FEDORA-2009-12560
https://www.redhat.com/archives/fedora-package-announce/2010-January/msg00166.html
FEDORA-2009-12575
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg01390.html
JVN#09758120
http://jvn.jp/en/jp/JVN09758120/index.html
JVNDB-2009-003901
http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-003901.html
RHSA-2010:0635
https://rhn.redhat.com/errata/RHSA-2010-0635.html
[oss-security] 20091125 CVE Request - Cacti - 0.8.7e
http://www.openwall.com/lists/oss-security/2009/11/25/2
[oss-security] 20091125 Re: CVE Request - Cacti - 0.8.7e
http://www.openwall.com/lists/oss-security/2009/11/25/4
[oss-security] 20091126 Re: CVE Request - Cacti - 0.8.7e
http://www.openwall.com/lists/oss-security/2009/11/26/1
[oss-security] 20091130 Re: CVE Request - Cacti - 0.8.7e
http://www.openwall.com/lists/oss-security/2009/11/30/2
cacti-name-xss(54388)
https://exchange.xforce.ibmcloud.com/vulnerabilities/54388
http://bugs.gentoo.org/show_bug.cgi?id=294573
http://docs.cacti.net/#cross-site_scripting_fixes
http://www.cacti.net/download_patches.php
http://www.cacti.net/downloads/patches/0.8.7e/cross_site_fix.patch
CopyrightCopyright (C) 2009 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.