|
|
Log in / Subscribe / Register

Arch Linux alert ASA-201707-30 (cacti)

From:  Remi Gacogne <rgacogne@archlinux.org>
To:  arch-security@archlinux.org
Subject:  [arch-security] [ASA-201707-30] cacti: cross-site scripting
Date:  Fri, 28 Jul 2017 10:58:02 +0200
Message-ID:  <621714fd-2c84-614f-f0ad-c33e36c8bddf@archlinux.org>

Arch Linux Security Advisory ASA-201707-30 ========================================== Severity: Medium Date : 2017-07-27 CVE-ID : CVE-2017-11691 Package : cacti Type : cross-site scripting Remote : Yes Link : https://security.archlinux.org/AVG-365 Summary ======= The package cacti before version 1.1.14-1 is vulnerable to cross-site scripting. Resolution ========== Upgrade to 1.1.14-1. # pacman -Syu "cacti>=1.1.14-1" The problem has been fixed upstream in version 1.1.14. Workaround ========== None. Description =========== A cross-site scripting vulnerability has been found in Cacti <= 1.1.13, in the user profile management page (auth_profile.php), allowing inject arbitrary web script or HTML via specially crafted HTTP Referer headers. Impact ====== A remote authenticated attacker might be able to inject arbitrary web script or HTML via crafted Referer headers. References ========== http://seclists.org/oss-sec/2017/q3/217 https://github.com/Cacti/cacti/issues/867 https://github.com/Cacti/cacti/commit/104090aeead4aa433bf... https://security.archlinux.org/CVE-2017-11691


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds