Accepted: cacti, cacti, cacti_0.8.6j-1.1ubuntu0.2_i386_translations.tar.gz 0.8.6j-1.1ubuntu0.2 (source, i386, raw-translations)

Ubuntu Installer archive at ubuntu.com
Fri Feb 22 02:55:38 GMT 2008


Accepted:
 OK: cacti_0.8.6j.orig.tar.gz
 OK: cacti_0.8.6j-1.1ubuntu0.2.diff.gz
 OK: cacti_0.8.6j-1.1ubuntu0.2.dsc
     -> Component: universe Section: web
 OK: cacti_0.8.6j-1.1ubuntu0.2_all.deb
 OK: cacti_0.8.6j-1.1ubuntu0.2_i386_translations.tar.gz

Format: 1.7
Date: Fri, 15 Feb 2008 20:26:11 +0100
Source: cacti
Binary: cacti
Architecture: i386_translations all source
Version: 0.8.6j-1.1ubuntu0.2
Distribution: gutsy-security
Urgency: low
Maintainer: Ubuntu MOTU Developers <ubuntu-motu at lists.ubuntu.com>
Changed-By: Stephan Hermann <sh at sourcecode.de>
Description:
 cacti      - Frontend to rrdtool for monitoring systems and services
Changes:
 cacti (0.8.6j-1.1ubuntu0.2) gutsy-security; urgency=low
 .
   * SECURITY UPDATE: (LP: #192199)
     + CVE-2008-0783: Multiple cross-site scripting (XSS) vulnerabilities in
       Cacti 0.8.7 before 0.8.7b and 0.8.6 before 0.8.6k allow remote attackers to
       inject arbitrary web script or HTML via the (1) view_type parameter to
       graph.php, (2) filter parameter to graph_view.php, and (3) action and
       login_username parameters to index.php/login.
     + CVE-2008-0784: graph.php in Cacti 0.8.7 before 0.8.7b and 0.8.6 before
       0.8.6k allows remote attackers to obtain the full path via an invalid
       local_graph_id parameter and other unspecified vectors.
   * debian/patches/11_CVE-2008-0783_CVE-2008-0784.dpatch: applied patch by
     upstream.
     (Link: http://www.cacti.net/downloads/patches/0.8.6j/multiple_vulnerabilities-0.8.6j.patch)
   * References:
     CVE-2008-0783
     CVE-2008-0784
Files:
 8ef4eed61f6584e0692cf261a778807b 960102 web extra cacti_0.8.6j-1.1ubuntu0.2_all.deb
 e395ff40d61c972dc5089fbc5d78f556 12669 raw-translations - cacti_0.8.6j-1.1ubuntu0.2_i386_translations.tar.gz
 2ae1dc9eea1073a7fc7dbe8ab1d7ea98 674 web extra cacti_0.8.6j-1.1ubuntu0.2.dsc
 73545b24a464fe6b6e6e18a15c48d5f2 36348 web extra cacti_0.8.6j-1.1ubuntu0.2.diff.gz
Launchpad-Bugs-Fixed: 192199
Original-Maintainer: sean finney <seanius at debian.org>





More information about the gutsy-changes mailing list