Debian Security Advisory

DLA-374-1 cacti -- LTS security update

Date Reported:
26 Dec 2015
Affected Packages:
cacti
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 807599.
In Mitre's CVE dictionary: CVE-2015-8369, CVE-2015-8377.
More information:

It was discovered that there were SQL injection vulnerabilities in cacti, a web interface for graphing of monitoring systems.

For Debian 6 Squeeze, this issue has been fixed in cacti version 0.8.7g-1+squeeze9+deb6u11.