[Pkg-cacti-maint] Bug#867532: cacti: CVE-2017-10970: XSS vulnerability via link.php

Salvatore Bonaccorso carnil at debian.org
Fri Jul 7 04:48:00 UTC 2017


Upstream commit 11e7294de8e344765d6fefd8295ca01f6b0fa7a7 introduced:

better validation log messages

If there is an unchecked request variable, let the developer know what
variable and what it was set to.

Unless I'm completely mistaken that should be the commit which
introduced the issue. As such stretch and jessie should not be
affected.

Regards,
Salvatore



More information about the Pkg-cacti-maint mailing list