HIGH
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays
Published Dec 12, 2019
8.1
HIGHCVSS 3.1
EPSS 3.03%
Description
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.
Affected products
Remediation
No remediation recorded yet.
References (14)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.html vendor-advisoryx_refsource_SUSE
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2019-17358 x_refsource_MISCIssue TrackingThird Party Advisory
- https://github.com/Cacti/cacti/blob/79f29cddb5eb05cbaff486cd634285ef1fed9326/lib/functions.php#L3109 x_refsource_MISCExploitThird Party Advisory
- https://github.com/Cacti/cacti/commit/adf221344359f5b02b8aed43dfb6b33ae5d708c8 x_refsource_MISCProductThird Party Advisory
- https://github.com/Cacti/cacti/issues/3026 x_refsource_MISCIssue TrackingThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/12/msg00014.html x_refsource_MISCMailing ListThird Party Advisory
- https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-17358.html x_refsource_MISCThird Party Advisory
- https://seclists.org/bugtraq/2020/Jan/25 mailing-listx_refsource_BUGTRAQ
- https://security.gentoo.org/glsa/202003-40 vendor-advisoryx_refsource_GENTOO
- https://www.darkmatter.ae/xen1thlabs/ x_refsource_MISCNot Applicable
- https://www.debian.org/security/2020/dsa-4604 vendor-advisoryx_refsource_DEBIAN
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 12, 2019
Updated Aug 5, 2024
Reserved Oct 8, 2019
Link CVE-2019-17358
CISA Vulnrichment
Updated n/a