U radu programskog paketa cacti uočeni su i ispravljeni sigurnosni propusti. Nije poznato na koji način potencijalni, zlonamjerni korisnik može iskoristiti sigurnosne nedostatke.
Paket:
cacti 0.x
Operacijski sustavi:
Fedora 15, Fedora 16
Problem:
neodgovarajuća provjera ulaznih podataka, XSS
Iskorištavanje:
udaljeno
Posljedica:
dobivanje većih privilegija
Rješenje:
programska zakrpa proizvođača
Izvorni ID preporuke:
FEDORA-2011-17015
Izvor:
Fedora
Problem:
Sigurnosni propusti se javljaju zbog nespecificirane pogreške.
Posljedica:
Nije poznato na koji način napadač može iskoristiti sigurnosne nedostatke.
Rješenje:
Rješenje problema sigurnosti je nadogradnja na novije inačice.
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-17015
2011-12-12 21:25:09
--------------------------------------------------------------------------------
Name : cacti
Product : Fedora 16
Version : 0.8.7i
Release : 2.fc16
URL : http://www.cacti.net/
Summary : An rrd based graphing tool
Description :
Cacti is a complete frontend to RRDTool. It stores all of the
necessary information to create graphs and populate them with
data in a MySQL database. The frontend is completely PHP
driven. Along with being able to maintain graphs, data
sources, and round robin archives in a database, Cacti also
handles the data gathering. There is SNMP support for those
used to creating traffic graphs with MRTG.
--------------------------------------------------------------------------------
Update Information:
Update to 0.8.7i. Upstream release notes are at
http://www.cacti.net/release_notes_0_8_7i.php. Notably "Multiple security
vulnerabilities". Also, adjust mod_security settings.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 13 2011 Ken Dreyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.8.7i-2
- Only set "su" logrotate parameter for F16 and above.
- Tweak mod_security rules.
* Mon Dec 12 2011 Ken Dreyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.8.7i-1
- New upstream release (BZ #766573).
* Fri Nov 11 2011 Ken Dreyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.8.7h-2
- block HTTP access to log and rra directories (#609856)
- overrides for mod_security
- set logrotate to su to cacti apache when rotating (#753079)
* Thu Oct 27 2011 Ken Dreyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.8.7h-1
- New upstream release.
- Remove upstream'd mysql patch.
* Mon Aug 8 2011 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.8.7g-3
- Patch for MySQL 5.5, BZ 728513.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #766573 - cacti-0.8.7i is available
https://bugzilla.redhat.com/show_bug.cgi?id=766573
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update cacti' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2011-17049
2011-12-12 21:27:18
--------------------------------------------------------------------------------
Name : cacti
Product : Fedora 15
Version : 0.8.7i
Release : 2.fc15
URL : http://www.cacti.net/
Summary : An rrd based graphing tool
Description :
Cacti is a complete frontend to RRDTool. It stores all of the
necessary information to create graphs and populate them with
data in a MySQL database. The frontend is completely PHP
driven. Along with being able to maintain graphs, data
sources, and round robin archives in a database, Cacti also
handles the data gathering. There is SNMP support for those
used to creating traffic graphs with MRTG.
--------------------------------------------------------------------------------
Update Information:
Update to 0.8.7i. Upstream release notes are at
http://www.cacti.net/release_notes_0_8_7i.php. Notably "Multiple security
vulnerabilities".
Also, adjust mod_security settings.
--------------------------------------------------------------------------------
ChangeLog:
* Tue Dec 13 2011 Ken Dreyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.8.7i-2
- Only set "su" logrotate parameter for F16 and above.
- Tweak mod_security rules.
* Mon Dec 12 2011 Ken Dreyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.8.7i-1
- New upstream release (BZ #766573).
* Fri Nov 11 2011 Ken Dreyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.8.7h-2
- block HTTP access to log and rra directories (#609856)
- overrides for mod_security
- set logrotate to su to cacti apache when rotating (#753079)
* Thu Oct 27 2011 Ken Dreyer <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.8.7h-1
- New upstream release.
- Remove upstream'd mysql patch.
* Mon Aug 8 2011 Jon Ciesla <Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.> - 0.8.7g-3
- Patch for MySQL 5.5, BZ 728513.
--------------------------------------------------------------------------------
References:
[ 1 ] Bug #766573 - cacti-0.8.7i is available
https://bugzilla.redhat.com/show_bug.cgi?id=766573
--------------------------------------------------------------------------------
This update can be installed with the "yum" update program. Use
su -c 'yum update cacti' at the command line.
For more information, refer to "Managing Software with yum",
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
--------------------------------------------------------------------------------
_______________________________________________
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.
https://admin.fedoraproject.org/mailman/listinfo/package-announce
Posljednje sigurnosne preporuke