Mageia alert MGASA-2017-0267 (cacti)
| From: | Mageia Updates <buildsystem-daemon@mageia.org> | |
| To: | updates-announce@ml.mageia.org | |
| Subject: | [updates-announce] MGASA-2017-0267: Updated cacti packages fix security vulnerabilities | |
| Date: | Mon, 14 Aug 2017 00:20:16 +0200 | |
| Message-ID: | <20170813222016.425709F871@duvel.mageia.org> |
MGASA-2017-0267 - Updated cacti packages fix security vulnerabilities Publication date: 13 Aug 2017 URL: http://advisories.mageia.org/MGASA-2017-0267.html Type: security Affected Mageia releases: 6 CVE: CVE-2017-10970, CVE-2017-11163, CVE-2017-11691, CVE-2017-12065, CVE-2017-12066 Description: Cross-site scripting (XSS) vulnerability in link.php in Cacti 1.1.12 allows remote anonymous users to inject arbitrary web script or HTML via the id parameter, related to the die_html_input_error function in lib/html_validate.php (CVE-2017-10970). Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti 1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable (CVE-2017-11163). A Cross-site scripting vulnerability exists in cacti before 1.1.14 in the user profile managment page (auth_profile.php), allowing inject arbitrary web script or HTML via specially crafted HTTP Referer headers (CVE-2017-11691). spikekill.php in Cacti before 1.1.16 might allow remote attackers to execute arbitrary code via the avgnan, outlier-start, or outlier-end parameter (CVE-2017-12065). Cross-site scripting (XSS) vulnerability in aggregate_graphs.php in Cacti before 1.1.16 allows remote authenticated users to inject arbitrary web script or HTML via specially crafted HTTP Referer headers, related to the $cancel_url variable (CVE-2017-12066). References: - https://bugs.mageia.org/show_bug.cgi?id=21242 - https://www.cacti.net/changelog.php - https://lists.fedoraproject.org/archives/list/package-ann... - http://openwall.com/lists/oss-security/2017/07/27/1 - https://lists.fedoraproject.org/archives/list/package-ann... - https://lists.opensuse.org/opensuse-updates/2017-08/msg00... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10970 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11163 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11691 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12065 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12066 SRPMS: - 6/core/cacti-1.1.16-1.mga6
