Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 7 Jun 2010 10:21:33 -0400 (EDT)
From: "Steven M. Christey" <coley@...us.mitre.org>
To: Jan Lieskovsky <jlieskov@...hat.com>
cc: oss-security@...ts.openwall.com, Nahuel Grisolia <nahuel@...sai-sec.com>,
        Stefan Esser <stefan.esser@...tioneins.de>,
        "Steven M. Christey" <coley@...us.mitre.org>,
        Cacti Developers <developers@...ti.net>,
        Tony Roman <roman@...order.com>
Subject: Re: CVE Request -- Cacti v0.8.7 -- three security
 fixes


On Tue, 1 Jun 2010, Jan Lieskovsky wrote:

>> [C], SQL injection and shell escaping issues reported by Bonsai Information 
>> Security (http://www.bonsai-sec.com)
>>            [7] 
>> http://www.bonsai-sec.com/blog/index.php/using-grep-to-find-0days/
>>            [8] 
>> http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-os-command-injection-0105.php
>>
>>
>>...
>>

>  2, OS command injection issue, CVE-2010-1645 / BONSAI-2010-0105
>     References:  [2] 
> http://www.bonsai-sec.com/en/research/vulnerabilities/cacti-os-command-injection-0105.php
>     Proper patches are the following three: (noticed by Tomas Hoger && 
> confirmed by Tony Roman, thanks for it!)
>       [3] http://svn.cacti.net/viewvc?view=rev&revision=5778
>       [4] http://svn.cacti.net/viewvc?view=rev&revision=5782
>       [5] http://svn.cacti.net/viewvc?view=rev&revision=5784

The BONSAI-2010-0105 references two problems, one for ping.php and another 
one having to do with a "Vertical Label" in a "Graph Template."

I don't see evidence of this vector in the revisions listed above.  Does 
anybody else?

(If the "Vertical Label" issue went unpatched, then a separate CVE should 
probably be assigned to it.)

- Steve

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.