Re: CVE-2015-8369 and 0.8.8g release
Christian Rebischke <[email protected]> Sun, 27 Dec 2015 22:46:28 +0100
| Newsgroups | gmane.network.cacti.user |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Dec 24, 2015 at 06:31:02AM +0100, Paul Gevers (Mobiel) wrote: > > This is the patch I applied in Debian. > > Paul > > http://anonscm.debian.org/cgit/pkg-cacti/cacti.git/tree/debian/patches/CVE-2015-8369_sql_injection_in_graph.php.patch > Hello Paul, I am not sure but I think Debian is using 0.8.8g or? Archlinux is still waiting for the official 0.8.8f release.. your patch is not working with 0.8.8f best regards -------------------------------------------------------------- Christian Rebischke Arch Linux Security Team Website : www.nullday.de Twitter : @sh1bumi Jabber : [email protected] PGP : 0xDFE2060D Fingerprint: 6DAF 7B80 8F9D F251 3962 0000 D214 61E3 DFE2 060D -------------------------------------------------------------- ------------------------------------------------------------------------------ _______________________________________________ cacti-user mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/cacti-user
signature.asc
(application/pgp-signature, 819 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQIcBAEBCAAGBQJWgFwzAAoJENIUYePf4gYNK3kQAL3poMB2BbInJpV8rI454tBk +21M9NnG7N+7M9N/WZCrPUaAQjTFpTtF800npLxnReLJZeOKB7Okdn20kSZCdkIj TuV4S9XEX9Auw8nsNi/9S5YpFzmRE1a/YHwUcgGGKKpoL55ZuDEceTfUOoryBh58 JqAzEegWKbLQZTqopN3VXpS0z23dBkzlHoYEzZQygLDoCC4978i10b8zAImBdgUf w71f+jxEUp4zQKdYQr4u4mYut4Wv38xJUdNf7eUbZ2+sN788bd4wF666/8U5w48B qMTxmraK9Gw4UGpKZ2jZCx7pzrc8IWIMww0/MhQ5l/Qz5jlgQjbHp8av1e/VBpWV 9FnA219tS3w0B3xfEeIxDR5zEtf+7EaggVIBxdHBO5k2L3A46KlEJ0JAKTPiP6Q/ HPGFzvNi4ng6tVlV0lNu/WLa1f1Eb0Z+XMN8trrZFyOQmY3uuxU6d7RLt2m2bwA+ /M+ncW3x9VeQfVmLrxMdSqjaikxCiUIFJdRzq19Qxel3igpeUQpkfkVBiHD7Oddq taRgm7WhqskLrhGFwnrJF0mHSdZmRcaIZeXHRdhBOo6sWtBXeVeW7vS4PH8ulXPp Zj28lYVUL2jxTxnLAvwNoFVI7AuCDm7NwrrGj5fk8exHZSEKiRiHTLqS5ZKciXrU Oeh9Cf/3BxMBnFAoxYxT =VKnj -----END PGP SIGNATURE-----