Overview

Request 358755 accepted

cacti was updated to fix the following vulnerabilities:

* CVE-2015-8369: SQL injection in graph.php (boo#958863)
* CVE-2015-8604: SQL injection in graphs_new.php (boo#960678)
* CVE-2015-8377: SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php (boo#958977)
* CVE-2016-2313: Authentication using web authentication as a user not in the cacti database allows complete access (boo#965930)

The following non-security bugs were fixed:

boo#965864: Poller Script Parser was broken (boo#965864)

cacti-spine was updated to match the cacti version, fixing a number of upstream bugs.

Request History
Andreas Stieger's avatar

AndreasStieger created request

cacti was updated to fix the following vulnerabilities:

* CVE-2015-8369: SQL injection in graph.php (boo#958863)
* CVE-2015-8604: SQL injection in graphs_new.php (boo#960678)
* CVE-2015-8377: SQL injection vulnerability in the host_new_graphs_save function in graphs_new.php (boo#958977)
* CVE-2016-2313: Authentication using web authentication as a user not in the cacti database allows complete access (boo#965930)

The following non-security bugs were fixed:

boo#965864: Poller Script Parser was broken (boo#965864)

cacti-spine was updated to match the cacti version, fixing a number of upstream bugs.


Wolfgang Rosenauer's avatar

wrosenauer accepted request

thanks

openSUSE Build Service is sponsored by