Bug 960678 (CVE-2015-8604) - VUL-0: CVE-2015-8604: cacti: SQL injection vulnerability in graphs_new.php
Summary: VUL-0: CVE-2015-8604: cacti: SQL injection vulnerability in graphs_new.php
Status: RESOLVED FIXED
Alias: CVE-2015-8604
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/160341/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-01-05 09:10 UTC by Johannes Segitz
Modified: 2018-08-03 22:12 UTC (History)
7 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2016-01-05 09:10:34 UTC
CVE-2015-8604

A SQL injection vulnerability via graphs_new.php in cacti was reported in http://bugs.cacti.net/view.php?id=2652

An exploit sample is provided in the bug.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8604
http://seclists.org/oss-sec/2016/q1/15
Comment 2 Andreas Stieger 2016-01-05 12:05:24 UTC
separate issue -  http://seclists.org/oss-sec/2016/q1/21
Comment 3 Swamp Workflow Management 2016-01-05 23:00:25 UTC
bugbot adjusting priority
Comment 4 Andreas Stieger 2016-02-09 14:10:47 UTC
Patch available for bug 958977 and bug 958978:
http://svn.cacti.net/viewvc?view=rev&revision=7772

Please submit.
Comment 5 Andreas Stieger 2016-02-09 14:15:44 UTC
Looks like catci does not have a clear primary bugowner.
I am taking bug 958863, bug 958977, bug 958977 and will submit unless someone else takes them and beats me to it.
Comment 7 Bernhard Wiedemann 2016-02-10 18:00:39 UTC
This is an autogenerated message for OBS integration:
This bug (960678) was mentioned in
https://build.opensuse.org/request/show/358753 42.1 / cacti-spine+cacti
https://build.opensuse.org/request/show/358754 13.2 / cacti-spine+cacti
https://build.opensuse.org/request/show/358755 13.1 / cacti
Comment 8 Andreas Stieger 2016-02-10 19:45:06 UTC
all submitted, updates running
Comment 9 Andreas Stieger 2016-02-12 06:13:09 UTC
Release updates
Comment 10 Swamp Workflow Management 2016-02-12 09:11:52 UTC
openSUSE-SU-2016:0437-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 958863,958977,960678,965864,965930
CVE References: CVE-2015-8369,CVE-2015-8377,CVE-2015-8604,CVE-2016-2313
Sources used:
openSUSE 13.2 (src):    cacti-0.8.8f-4.13.1, cacti-spine-0.8.8f-4.3.1
Comment 11 Swamp Workflow Management 2016-02-12 09:13:04 UTC
openSUSE-SU-2016:0438-1: An update that fixes four vulnerabilities is now available.

Category: security (moderate)
Bug References: 958863,958977,960678,965930
CVE References: CVE-2015-8369,CVE-2015-8377,CVE-2015-8604,CVE-2016-2313
Sources used:
openSUSE Leap 42.1 (src):    cacti-0.8.8f-8.1, cacti-spine-0.8.8f-5.1
Comment 12 Swamp Workflow Management 2016-02-12 13:11:37 UTC
openSUSE-SU-2016:0440-1: An update that solves four vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 958863,958977,960678,965864,965930
CVE References: CVE-2015-8369,CVE-2015-8377,CVE-2015-8604,CVE-2016-2313
Sources used:
openSUSE 13.1 (src):    cacti-0.8.8f-17.1
Comment 13 Swamp Workflow Management 2018-07-28 18:11:33 UTC
This is an autogenerated message for OBS integration:
This bug (960678) was mentioned in
https://build.opensuse.org/request/show/625957 Backports:SLE-12 / cacti
Comment 14 Swamp Workflow Management 2018-08-03 22:12:41 UTC
openSUSE-OU-2018:2194-1: An update that fixes 33 vulnerabilities is now available.

Category: optional (low)
Bug References: 022564,1047512,1048102,1050950,1051633,1054390,1054742,1067163,1067164,1067166,1068028,1101024,1101139,837440,862993,867607,870821,872008,934187,937997,958863,958977,960678,965930,971357,974013
CVE References: CVE-2006-6799,CVE-2007-3112,CVE-2007-3113,CVE-2013-5588,CVE-2013-5589,CVE-2014-2326,CVE-2014-2327,CVE-2014-2328,CVE-2014-2708,CVE-2014-2709,CVE-2014-4000,CVE-2014-4002,CVE-2014-5025,CVE-2014-5026,CVE-2015-4342,CVE-2015-4634,CVE-2015-8369,CVE-2015-8377,CVE-2015-8604,CVE-2016-2313,CVE-2016-3172,CVE-2016-3659,CVE-2017-10970,CVE-2017-11163,CVE-2017-11691,CVE-2017-12065,CVE-2017-12927,CVE-2017-12978,CVE-2017-15194,CVE-2017-16641,CVE-2017-16660,CVE-2017-16661,CVE-2017-16785
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    cacti-1.1.38-2.1