Re: CVE-2015-8369 and 0.8.8g release

Paul Gevers <[email protected]> Thu, 24 Dec 2015 07:43:24 +0100
Newsgroups gmane.network.cacti.user
Message-ID <[email protected]>
Hi Christian,

On 23-12-15 16:25, Christian Rebischke wrote:
> I have a question. Do you have a patch for the CVE-2015-8369 for cacti in
> version 0.8.8f? I checked out your SVN repository and generated the
> following patch: https://paste.archlinux.de/yPT/ 
> My problem is that this patch has been generated via diff between r7766 and
> r7767 so It will not work when I apply it to our cacti version (0.8.8f) in
> our official archlinux repositories, because the difference between 0.8.8f
> and your patch is too far.

This is the patch I applied in Debian:
http://anonscm.debian.org/cgit/pkg-cacti/cacti.git/tree/debian/patches/CVE-2015-8369_sql_injection_in_graph.php.patch

It is based on the same commit, but I had no issues with it (I can't
even remember if I had to adjust it or not).

Paul

------------------------------------------------------------------------------

_______________________________________________
cacti-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/cacti-user
signature.asc (application/pgp-signature, 473 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWe5QNAAoJEJxcmesFvXUKgFoIALbzMT6JyXespzn13cvyBK4u
i29PgXZd3HmDU/Sk0o90llsqakVqjj/Ztb7l5ydkPFaUIIGs3pI9kwTbq1T9hNYu
xchSq49QRtetZdkO1pmz5HW14ub3RtRS0/1R1IG3nfhODYU7t4n7pn1H5b86HmBq
/2I1DXt00PHQMHecBcJsx0s0Fl9ZoA5M4BStVHd/14c2o6zmAS+ugunAF+P/RVgu
LpkzoHQ9ibtF6qpcSXzBGjmJIEKqDxXYnx0i4ARdF6EiSwdwe4MVazkHbYe3LQ8B
lBoA31YwZOlfUhulGtkrohQnNqcHlBRWhNM0aNY+0JLu3tQ97PWyMsqBFDw0WqM=
=mWPN
-----END PGP SIGNATURE-----