[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2023-49084/cacti: follow-up patch + mitigation note

Sylvain Beucler (@beuc) beuc at debian.org
Tue Feb 27 10:44:56 GMT 2024



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a8640782 by Sylvain Beucler at 2024-02-27T11:42:15+01:00
CVE-2023-49084/cacti: follow-up patch + mitigation note

- - - - -
8d95dc5b by Sylvain Beucler at 2024-02-27T11:43:48+01:00
CVE-2023-49085/cacti: add note

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -12466,6 +12466,7 @@ CVE-2023-49085 (Cacti provides an operational monitoring and fault management fr
 	- cacti 1.2.26+ds1-1
 	NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-vr3c-38wh-g855
 	NOTE: https://github.com/Cacti/cacti/commit/5f451bc680d7584525d18026836af2a1e31b2188 (release/1.2.26)
+	NOTE: Requires multi-pollers setup
 CVE-2023-48704 (ClickHouse is an open-source column-oriented database management syste ...)
 	- clickhouse <unfixed> (bug #1059367)
 	[bookworm] - clickhouse <no-dsa> (Minor issue)
@@ -12587,6 +12588,8 @@ CVE-2023-49084 (Cacti is a robust performance and fault management framework and
 	- cacti 1.2.26+ds1-1 (bug #1059254)
 	NOTE: https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp
 	NOTE: https://github.com/Cacti/cacti/commit/5f451bc680d7584525d18026836af2a1e31b2188 (release/1.2.26)
+	NOTE: https://github.com/Cacti/cacti/commit/c3a647e9867ae8e2982e26342630ba9edb2d94b7 (release/1.2.26)
+	NOTE: Mitigated in Debian by not shipping or creating 'include/content/'
 CVE-2023-48723
 	REJECTED
 CVE-2023-48722 (Student Result Management System v1.0 is vulnerable to multiple Unauth ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c17c219bb6c244fa50ea884d7a0b4c4bcfb0bf05...8d95dc5bec06c31c652bddd8df274941a82fc993

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c17c219bb6c244fa50ea884d7a0b4c4bcfb0bf05...8d95dc5bec06c31c652bddd8df274941a82fc993
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240227/75d486f3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list