Gentoo Archives: gentoo-announce

From: Kurt Lieber <klieber@g.o>
To: gentoo-announce@l.g.o
Cc: bugtraq@×××××××××××××.com, full-disclosure@××××××××××××.com, security-alerts@×××××××××××××.com
Subject: [gentoo-announce] [ GLSA 200408-21 ] Cacti: SQL injection vulnerability
Date: Mon, 23 Aug 2004 12:30:12
Message-Id: 20040823122835.GJ29077@mail.lieber.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 200408-21
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 http://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Cacti: SQL injection vulnerability
9 Date: August 23, 2004
10 Bugs: #60630
11 ID: 200408-21
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 With special configurations of Cacti it is possible to change passwords
19 via a SQL injection attack.
20
21 Background
22 ==========
23
24 Cacti is a complete web-based front end to rrdtool.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 net-analyzer/cacti <= 0.8.5a >= 0.8.5a-r1
33
34 Description
35 ===========
36
37 Cacti is vulnerable to a SQL injection attack where an attacker may
38 inject SQL into the Username field.
39
40 Impact
41 ======
42
43 An attacker could use these vulnerabilities to compromise the Cacti
44 service and potentially execute programs with the permissions of the
45 user running Cacti.
46
47 Workaround
48 ==========
49
50 To prevent SQL code injection, php_flag magic_quotes_gpc should be set
51 to Off. By default, Gentoo Linux installs PHP with this option set to
52 Off.
53
54 Resolution
55 ==========
56
57 All users should upgrade to the latest available version of Cacti, as
58 follows:
59
60 # emerge sync
61
62 # emerge -pv ">=net-analyzer/cacti-0.8.5a-r1"
63 # emerge ">=net-analyzer/cacti-0.8.5a-r1"
64
65 References
66 ==========
67
68 [ 1 ] Full Disclosure Announcement
69 http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0717.html
70
71 Availability
72 ============
73
74 This GLSA and any updates to it are available for viewing at
75 the Gentoo Security Website:
76
77 http://security.gentoo.org/glsa/glsa-200408-21.xml
78
79 Concerns?
80 =========
81
82 Security is a primary focus of Gentoo Linux and ensuring the
83 confidentiality and security of our users machines is of utmost
84 importance to us. Any security concerns should be addressed to
85 security@g.o or alternatively, you may file a bug at
86 http://bugs.gentoo.org.
87
88 License
89 =======
90
91 Copyright 2004 Gentoo Foundation, Inc; referenced text
92 belongs to its owner(s).
93
94 The contents of this document are licensed under the
95 Creative Commons - Attribution / Share Alike license.
96
97 http://creativecommons.org/licenses/by-sa/1.0