Re: CVE-2015-8369 and 0.8.8g release
Paul Gevers <[email protected]> Thu, 24 Dec 2015 07:43:24 +0100
| Newsgroups | gmane.network.cacti.user |
|---|---|
| Message-ID | <[email protected]> |
Hi Christian, On 23-12-15 16:25, Christian Rebischke wrote: > I have a question. Do you have a patch for the CVE-2015-8369 for cacti in > version 0.8.8f? I checked out your SVN repository and generated the > following patch: https://paste.archlinux.de/yPT/ > My problem is that this patch has been generated via diff between r7766 and > r7767 so It will not work when I apply it to our cacti version (0.8.8f) in > our official archlinux repositories, because the difference between 0.8.8f > and your patch is too far. This is the patch I applied in Debian: http://anonscm.debian.org/cgit/pkg-cacti/cacti.git/tree/debian/patches/CVE-2015-8369_sql_injection_in_graph.php.patch It is based on the same commit, but I had no issues with it (I can't even remember if I had to adjust it or not). Paul ------------------------------------------------------------------------------ _______________________________________________ cacti-user mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/cacti-user
signature.asc
(application/pgp-signature, 473 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQEcBAEBCAAGBQJWe5QNAAoJEJxcmesFvXUKgFoIALbzMT6JyXespzn13cvyBK4u i29PgXZd3HmDU/Sk0o90llsqakVqjj/Ztb7l5ydkPFaUIIGs3pI9kwTbq1T9hNYu xchSq49QRtetZdkO1pmz5HW14ub3RtRS0/1R1IG3nfhODYU7t4n7pn1H5b86HmBq /2I1DXt00PHQMHecBcJsx0s0Fl9ZoA5M4BStVHd/14c2o6zmAS+ugunAF+P/RVgu LpkzoHQ9ibtF6qpcSXzBGjmJIEKqDxXYnx0i4ARdF6EiSwdwe4MVazkHbYe3LQ8B lBoA31YwZOlfUhulGtkrohQnNqcHlBRWhNM0aNY+0JLu3tQ97PWyMsqBFDw0WqM= =mWPN -----END PGP SIGNATURE-----