[Pkg-cacti-maint] Bug#947374: cacti: CVE-2019-17357: does not seem to affect stretch

Chris Lamb lamby at debian.org
Sun Dec 29 18:03:15 GMT 2019


Hi Hugo,

> rationale: template_id is sanitized at line 1048:
> input_validate_input_number(get_request_var_request("template_id"));
[…]
> Chris: you worked on cacti in jessie and triaged it not-affected. Jessie
> has a similar version, does this match your findings?

Ah yes; well-spotted. :)


Regards,

-- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby at debian.org 🍥 chris-lamb.co.uk
       `-



More information about the Pkg-cacti-maint mailing list