CVE-2014-2327

NameCVE-2014-2327
DescriptionCross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-2970-1
NVD severitymedium (attack range: remote, user-initiated)
Debian Bugs742768
Debian/oldoldstablepackage cacti is vulnerable.
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cacti (PTS)squeeze, squeeze (security)0.8.7g-1+squeeze3vulnerable
squeeze (lts)0.8.7g-1+squeeze8fixed
wheezy0.8.8a+dfsg-5+deb7u4fixed
wheezy (security)0.8.8a+dfsg-5+deb7u6fixed
jessie0.8.8b+dfsg-8fixed
jessie (security)0.8.8b+dfsg-8+deb8u2fixed
stretch, sid0.8.8f+ds1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cactisource(unstable)0.8.8b+dfsg-6medium742768
cactisourcesqueeze0.8.7g-1+squeeze4medium742768
cactisourcewheezy0.8.8a+dfsg-5+deb7u3mediumDSA-2970-1

Notes

http://bugs.cacti.net/view.php?id=2432

Search for package or bug name: Reporting problems