[Git][security-tracker-team/security-tracker][master] CVE-2019-16723/cacti: jessie/stretch not affected

Hugo Lefeuvre hle at debian.org
Thu Oct 17 13:02:00 BST 2019



Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e35e4bf7 by Hugo Lefeuvre at 2019-10-17T11:59:10Z
CVE-2019-16723/cacti: jessie/stretch not affected

c.f. Debian bug report for more information, upstream ack-ed on
upstream bug report.

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -2357,6 +2357,11 @@ CVE-2019-16724 (File Sharing Wizard 1.5.0 allows a remote attacker to obtain arb
 	NOT-FOR-US: File Sharing Wizard
 CVE-2019-16723 (In Cacti through 1.2.6, authenticated users may bypass authorization c ...)
 	- cacti 1.2.7+ds1-1 (bug #941036)
+	[stretch] - cacti <not-affected> (vulnerability introduced later)
+	[jessie] - cacti <not-affected> (vulnerability introduced later)
+	NOTE: vulnerability introduced in
+	NOTE: https://github.com/Cacti/cacti/commit/cf73ae1a9f65b5a27d7f9d10c8e14835c3a76326
+	NOTE: see Debian bug report for more explanations
 	NOTE: https://github.com/Cacti/cacti/issues/2964
 	NOTE: https://github.com/Cacti/cacti/commit/7a6a17252a1cbda180b61fff244cb3ce797d5264
 	NOTE: https://github.com/Cacti/cacti/commit/c7cf4a26e4848872b48094e67f8d0a01dd7613d2


=====================================
data/dla-needed.txt
=====================================
@@ -16,13 +16,6 @@ ampache (Roberto C. Sánchez)
 ansible (Utkarsh Gupta)
   NOTE: 20191011: Code appears to be in lib/ansible/callbacks.py in jessie's version. (lamby)
 --
-cacti (Hugo Lefeuvre)
-  NOTE: 20191016: jessie and stretch don't seem to be affected, see
-  NOTE: https://lists.debian.org/debian-lts/2019/10/msg00081.html for more details
-  NOTE: waiting for feedback from upstream: https://github.com/Cacti/cacti/issues/2964
-  NOTE: 20190117: upstream answered positively. waiting for him to rework a few things
-  NOTE: before updating the tracker.
---
 freeimage (Hugo Lefeuvre)
   NOTE: Maintainer will take care of the update.
   NOTE: https://lists.debian.org/debian-lts/2019/05/msg00079.html



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e35e4bf731f3e261e92f30d5b16cd43632acd70a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/e35e4bf731f3e261e92f30d5b16cd43632acd70a
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20191017/7f564fe8/attachment-0001.html>


More information about the debian-security-tracker-commits mailing list