Updated cacti packages fix security vulnerabilities
Publication date: 13 Aug 2017Modification date: 13 Aug 2017
Type: security
Affected Mageia releases : 6
CVE: CVE-2017-10970 , CVE-2017-11163 , CVE-2017-11691 , CVE-2017-12065 , CVE-2017-12066
Description
Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12
allows remote anonymous users to inject arbitrary web script or HTML
via the id parameter, related to the die_html_input_error function in
lib/html_validate.php (CVE-2017-10970).
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in
Cacti 1.1.12 allows remote authenticated users to inject arbitrary web
script or HTML via specially crafted HTTP Referer headers, related to
the $cancel_url variable (CVE-2017-11163).
A Cross-site scripting vulnerability exists in cacti before 1.1.14 in
the user profile managment page (auth_profile.php), allowing inject
arbitrary web script or HTML via specially crafted HTTP Referer headers
(CVE-2017-11691).
spikekill.php in Cacti before 1.1.16 might allow remote attackers to
execute arbitrary code via the avgnan, outlier-start, or outlier-end
parameter (CVE-2017-12065).
Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in
Cacti before 1.1.16 allows remote authenticated users to inject
arbitrary web script or HTML via specially crafted HTTP Referer headers,
related to the $cancel_url variable (CVE-2017-12066).
References
- https://bugs.mageia.org/show_bug.cgi?id=21242
- https://www.cacti.net/changelog.php
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/7MRJCGVNDLW7RCTYSL72XGP74PCMOIH2/
- http://openwall.com/lists/oss-security/2017/07/27/1
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/QN75M6HGIKEEX7HYFWHIO6IYDB5RXFP6/
- https://lists.opensuse.org/opensuse-updates/2017-08/msg00018.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10970
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11163
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11691
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12065
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12066
SRPMS
6/core
- cacti-1.1.16-1.mga6