From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from lists.gentoo.org ([140.105.134.102] helo=robin.gentoo.org) by finch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1J033i-0001kW-Tg for garchives@archives.gentoo.org; Wed, 05 Dec 2007 22:49:39 +0000 Received: from robin.gentoo.org (localhost [127.0.0.1]) by robin.gentoo.org (8.14.2/8.14.0) with SMTP id lB5MnZ0j019737; Wed, 5 Dec 2007 22:49:36 GMT Received: from smtp.gentoo.org (smtp.gentoo.org [140.211.166.183]) by robin.gentoo.org (8.14.2/8.14.0) with ESMTP id lB5MnYA2019696 for ; Wed, 5 Dec 2007 22:49:35 GMT Received: from stork.gentoo.org (stork.gentoo.org [64.127.104.133]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.gentoo.org (Postfix) with ESMTP id 98D51653C8 for ; Wed, 5 Dec 2007 22:49:34 +0000 (UTC) Received: from py by stork.gentoo.org with local (Exim 4.60) (envelope-from ) id 1J02ow-000369-Ss for gentoo-commits@lists.gentoo.org; Wed, 05 Dec 2007 22:34:22 +0000 From: "Pierre-Yves Rofes (py)" To: gentoo-commits@lists.gentoo.org Reply-To: gentoo-dev@lists.gentoo.org, py@gentoo.org Subject: [gentoo-commits] gentoo commit in xml/htdocs/security/en/glsa: glsa-200712-02.xml X-VCS-Repository: gentoo X-VCS-Files: glsa-200712-02.xml X-VCS-Directories: xml/htdocs/security/en/glsa X-VCS-Committer: py X-VCS-Committer-Name: Pierre-Yves Rofes Content-Type: text/plain; charset=utf8 Content-Transfer-Encoding: 8bit Message-Id: Sender: Pierre-Yves Rofes Date: Wed, 05 Dec 2007 22:34:22 +0000 Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-commits@gentoo.org X-Archives-Salt: a6b8fc18-a1fb-4889-90a5-a624d5ad0eac X-Archives-Hash: cb290ab1fee00ed43ff7b77515823f91 py 07/12/05 22:34:22 Added: glsa-200712-02.xml Log: GLSA 200712-02 Revision Changes Path 1.1 xml/htdocs/security/en/glsa/glsa-200712-02.xml file : http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/security/en/glsa/glsa-200712-02.xml?rev=1.1&view=markup plain: http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/security/en/glsa/glsa-200712-02.xml?rev=1.1&content-type=text/plain Index: glsa-200712-02.xml =================================================================== Cacti: SQL injection An SQL injection vulnerability has been discovered in Cacti. cacti December 05, 2007 December 05, 2007: 01 199509 remote 0.8.6j-r7 0.8.7a 0.8.7a

Cacti is a complete web-based frontend to rrdtool.

It has been reported that the "local_graph_id" variable used in the file graph.php is not properly sanitized before being processed in an SQL statement.

A remote attacker could send a specially crafted request to the vulnerable host, possibly resulting in the execution of arbitrary SQL code.

There is no known workaround at this time.

All Cacti users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/cacti-0.8.6j-r7"
CVE-2007-6035 p-y p-y p-y
-- gentoo-commits@gentoo.org mailing list