Bugzilla – Bug 1122535
VUL-1: CVE-2009-4112: cacti: Privilege escalation under certain conditions
Last modified: 2020-04-30 19:23:01 UTC
From https://github.com/Cacti/cacti/issues/1072 " CVE-2009-4112 still exists (after 8 years) #1072 " This re-occurrence is now about creating new data input methods rather than modifying existing ones. Mitigation in upstream 1.2.0.
Leap 15.1 ships cacti version 1.1.38, which is still vulnerable.
This is an autogenerated message for OBS integration: This bug (1122535) was mentioned in https://build.opensuse.org/request/show/769371 15.1+Backports:SLE-15-SP1 / cacti+cacti-spine
This is an autogenerated message for OBS integration: This bug (1122535) was mentioned in https://build.opensuse.org/request/show/774590 15.1 / cacti+cacti-spine
openSUSE-SU-2020:0272-1: An update that solves 10 vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1082318,1101024,1101139,1122242,1122243,1122244,1122245,1122535,1158990,1158992,1161297,1163749 CVE References: CVE-2009-4112,CVE-2018-20723,CVE-2018-20724,CVE-2018-20725,CVE-2018-20726,CVE-2019-16723,CVE-2019-17357,CVE-2019-17358,CVE-2020-7106,CVE-2020-7237 Sources used: openSUSE Leap 15.1 (src): cacti-1.2.9-lp151.3.3.1, cacti-spine-1.2.9-lp151.3.3.1
openSUSE-SU-2020:0284-1: An update that solves 10 vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1082318,1101024,1101139,1122242,1122243,1122244,1122245,1122535,1158990,1158992,1161297,1163749 CVE References: CVE-2009-4112,CVE-2018-20723,CVE-2018-20724,CVE-2018-20725,CVE-2018-20726,CVE-2019-16723,CVE-2019-17357,CVE-2019-17358,CVE-2020-7106,CVE-2020-7237 Sources used: openSUSE Backports SLE-15-SP1 (src): cacti-1.2.9-bp151.4.3.1, cacti-spine-1.2.9-bp151.4.3.1
done
This is an autogenerated message for OBS integration: This bug (1122535) was mentioned in https://build.opensuse.org/request/show/793099 15.1+Backports:SLE-12 / cacti+cacti-spine
openSUSE-SU-2020:0558-1: An update that fixes 11 vulnerabilities is now available. Category: security (important) Bug References: 1082318,1122242,1122243,1122244,1122245,1122535,1158990,1158992,1161297,1164675,1169215 CVE References: CVE-2009-4112,CVE-2018-20723,CVE-2018-20724,CVE-2018-20725,CVE-2018-20726,CVE-2019-16723,CVE-2019-17357,CVE-2019-17358,CVE-2020-7106,CVE-2020-7237,CVE-2020-8813 Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): cacti-1.2.11-5.1, cacti-spine-1.2.11-2.1
openSUSE-SU-2020:0558-1: An update that fixes 11 vulnerabilities is now available. Category: security (important) Bug References: 1082318,1122242,1122243,1122244,1122245,1122535,1158990,1158992,1161297,1164675,1169215 CVE References: CVE-2009-4112,CVE-2018-20723,CVE-2018-20724,CVE-2018-20725,CVE-2018-20726,CVE-2019-16723,CVE-2019-17357,CVE-2019-17358,CVE-2020-7106,CVE-2020-7237,CVE-2020-8813 Sources used: openSUSE Leap 15.1 (src): cacti-1.2.11-lp151.3.6.1, cacti-spine-1.2.11-lp151.3.6.1 SUSE Package Hub for SUSE Linux Enterprise 12 (src): cacti-1.2.11-5.1, cacti-spine-1.2.11-2.1
openSUSE-SU-2020:0565-1: An update that fixes 11 vulnerabilities is now available. Category: security (important) Bug References: 1082318,1122242,1122243,1122244,1122245,1122535,1158990,1158992,1161297,1164675,1169215 CVE References: CVE-2009-4112,CVE-2018-20723,CVE-2018-20724,CVE-2018-20725,CVE-2018-20726,CVE-2019-16723,CVE-2019-17357,CVE-2019-17358,CVE-2020-7106,CVE-2020-7237,CVE-2020-8813 Sources used: openSUSE Backports SLE-15-SP1 (src): cacti-1.2.11-bp151.4.6.1, cacti-spine-1.2.11-bp151.4.6.1