Bug 884326 (CVE-2014-4002) - VUL-0: CVE-2014-4002: cacti: Cross-Site Scripting Vulnerability
Summary: VUL-0: CVE-2014-4002: cacti: Cross-Site Scripting Vulnerability
Status: RESOLVED FIXED
Alias: CVE-2014-4002
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.1
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Joop Boonen
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/100009/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-06-25 12:14 UTC by Johannes Segitz
Modified: 2015-06-11 09:51 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2014-06-25 12:14:30 UTC
Cacti upstream's svn
http://svn.cacti.net/viewvc?view=rev&revision=7452
has a fix for CVE-2014-4002.

No more technical information is available unfortunately.

It might be that also the change before this revision is also involved 
http://svn.cacti.net/viewvc?view=rev&revision=7451

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1113035
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-4002
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-4002
Comment 1 Swamp Workflow Management 2014-06-25 22:00:27 UTC
bugbot adjusting priority
Comment 2 Andreas Stieger 2015-06-11 09:51:41 UTC
Already fixed, openSUSE 13.1 and 13.2 are at 0.8.8c via version update.