[Git][security-tracker-team/security-tracker][master] CVE-2023-39362/cacti: note limitations

Sylvain Beucler (@beuc) beuc at debian.org
Mon Feb 26 20:01:27 GMT 2024



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
37ae384b by Sylvain Beucler at 2024-02-26T20:59:28+01:00
CVE-2023-39362/cacti: note limitations

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -31020,6 +31020,8 @@ CVE-2023-39362 (Cacti is an open source operational monitoring and fault managem
 	NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
 	NOTE: https://github.com/cacti/cacti/commit/cb9ab92f2580fc6cb9b64ce129655fb15e35d056 (release/1.2.25)
 	NOTE: https://github.com/Cacti/cacti/commit/4c26f39fa3567553192823a5e8096b187bbaddde (release/1.2.25)
+	NOTE: snmp_escape_string broken and non-exploitable until https://github.com/Cacti/cacti/commit/c66d5815b8381eaa7ef679abc8d041f23105ef34 (release/1.2.23)
+	NOTE: Requires php-snmp be disabled.
 CVE-2023-39361 (Cacti is an open source operational monitoring and fault management fr ...)
 	{DSA-5550-1}
 	- cacti 1.2.25+ds1-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/37ae384b58b7a3497aae605ed7b6fbbd9898b1e1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/37ae384b58b7a3497aae605ed7b6fbbd9898b1e1
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240226/f7f35961/attachment.htm>


More information about the debian-security-tracker-commits mailing list