Dag: cacti-0.8.6d needs a security update
Sitsofe Wheeler <[email protected]>
| Newsgroups | gmane.linux.freshrpms.user |
|---|---|
| Message-ID | <[email protected]> |
Hello, I've posted this once but I'm resending again in case my original post was overlooked. cacti-0.8.6d-1.1.fc3.rf has multiple security issues (as does 0.8.6e) (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-1524 ) within it that I am sad to say are being VERY actively exploited via Google searches in a similar way to the AWStats security holes of a few months ago (http://lists.freshrpms.net/pipermail/freshrpms-list/2005-February/012415.html ). There is a new version 0.8.6f of cacti (http://www.cacti.net/ ) that fixes these holes. Dag can you pull your 0.8.6d RPMs and replace them with 0.8.6f ones? -- Sitsofe | http://sucs.org/~sits/