[Bug 243592] New: CVE-2007-3112, CVE-2007-3113: cacti DoS vulnerabilities

bugzilla at redhat.com bugzilla at redhat.com
Sun Jun 10 09:54:53 UTC 2007


Please do not reply directly to this email. All additional
comments should be made in the comments box of this bug report.




https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=243592

           Summary: CVE-2007-3112, CVE-2007-3113: cacti DoS vulnerabilities
           Product: Fedora Extras
           Version: f7
          Platform: All
        OS/Version: Linux
            Status: NEW
          Severity: medium
          Priority: medium
         Component: cacti
        AssignedTo: mmcgrath at redhat.com
        ReportedBy: ville.skytta at iki.fi
         QAContact: extras-qa at fedoraproject.org
                CC: fedora-security-list at redhat.com


http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-3112
"Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to
cause a denial of service (CPU consumption) via a large value of the (1)
graph_start or (2) graph_end parameter."

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-3113
"Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to
cause a denial of service (CPU consumption) via a large value of the (1)
graph_height or (2) graph_width parameter."

The patch linked to in the reports applies to 0.8.6j too.

-- 
Configure bugmail: https://bugzilla.redhat.com/bugzilla/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug, or are watching someone who is.




More information about the security mailing list