Dag - Please update your cacti RPM
Sitsofe Wheeler <[email protected]>
| Newsgroups | gmane.linux.freshrpms.user |
|---|---|
| Message-ID | <[email protected]> |
(I'm using this list because it proved effective last time) cacti-0.8.6d-1.1.fc3.rf has multiple security issues (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1524 ) within it that I am sad to say are being VERY actively exploited via Google searches in a similar way to the AWStats security holes of a few months ago (http://lists.freshrpms.net/pipermail/freshrpms-list/2005-February/012415.html ). There is a new version 0.8.6e of cacti that fixes these holes. Folks, if you aren't using selinux now is the time to turn it on because we these sorts of exploits are only on the rise : ( Demanding instantly updated RPMs for security holes from an overstretched volunteer effort simply isn't fair. -- Sitsofe | http://sucs.org/~sits/