[Git][security-tracker-team/security-tracker][master] CVE-2019-16723/cacti: jessie/stretch not affected
Hugo Lefeuvre
hle at debian.org
Thu Oct 17 13:02:00 BST 2019
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e35e4bf7 by Hugo Lefeuvre at 2019-10-17T11:59:10Z
CVE-2019-16723/cacti: jessie/stretch not affected
c.f. Debian bug report for more information, upstream ack-ed on
upstream bug report.
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -2357,6 +2357,11 @@ CVE-2019-16724 (File Sharing Wizard 1.5.0 allows a remote attacker to obtain arb
NOT-FOR-US: File Sharing Wizard
CVE-2019-16723 (In Cacti through 1.2.6, authenticated users may bypass authorization c ...)
- cacti 1.2.7+ds1-1 (bug #941036)
+ [stretch] - cacti <not-affected> (vulnerability introduced later)
+ [jessie] - cacti <not-affected> (vulnerability introduced later)
+ NOTE: vulnerability introduced in
+ NOTE: https://github.com/Cacti/cacti/commit/cf73ae1a9f65b5a27d7f9d10c8e14835c3a76326
+ NOTE: see Debian bug report for more explanations
NOTE: https://github.com/Cacti/cacti/issues/2964
NOTE: https://github.com/Cacti/cacti/commit/7a6a17252a1cbda180b61fff244cb3ce797d5264
NOTE: https://github.com/Cacti/cacti/commit/c7cf4a26e4848872b48094e67f8d0a01dd7613d2
=====================================
data/dla-needed.txt
=====================================
@@ -16,13 +16,6 @@ ampache (Roberto C. Sánchez)
ansible (Utkarsh Gupta)
NOTE: 20191011: Code appears to be in lib/ansible/callbacks.py in jessie's version. (lamby)
--
-cacti (Hugo Lefeuvre)
- NOTE: 20191016: jessie and stretch don't seem to be affected, see
- NOTE: https://lists.debian.org/debian-lts/2019/10/msg00081.html for more details
- NOTE: waiting for feedback from upstream: https://github.com/Cacti/cacti/issues/2964
- NOTE: 20190117: upstream answered positively. waiting for him to rework a few things
- NOTE: before updating the tracker.
---
freeimage (Hugo Lefeuvre)
NOTE: Maintainer will take care of the update.
NOTE: https://lists.debian.org/debian-lts/2019/05/msg00079.html
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e35e4bf731f3e261e92f30d5b16cd43632acd70a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e35e4bf731f3e261e92f30d5b16cd43632acd70a
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191017/7f564fe8/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list