Nessus Plugin #15001
Plugin Index
Note: This file has been created from a
downloaded version of the Nessus Plugins
from
http://www.nessus.org/.
Therefore, the information here can be outdated.
[DSA164] DSA-164-1 cacti
- Family:
- Debian Local Security Checks
- Category:
- infos
- Copyright:
- This script is (C) 2004 Michel Arboi
- Summary:
- DSA-164-1 cacti
- Version:
- $Revision: 1.4 $
- Cve_id:
- CAN-2002-1477, CVE-2002-1478
- Bugtraq_id:
- -
- Xrefs:
- DSA:164
- Description:
A problem in cacti, a PHP based frontend to rrdtool for monitoring
systems and services, has been discovered. This could lead into cacti
executing arbitrary program code under the user id of the web server.
This problem, however, is only persistent to users who already have
administrator privileges in the cacti system.
This problem has been fixed by removing any dollar signs and backticks
from the title string in version 0.6.7-2.1 for the current stable
distribution (woody) and in version 0.6.8a-2 for the unstable
distribution (sid). The old stable distribution (potato) is not
affected since it doesn't contain the cacti package.
We recommend that you upgrade your cacti package immediately.
Solution : http://www.debian.org/security/2002/dsa-164
Risk factor : High
Generiert am 27.04.2005 um 18:49:54 Uhr.