USN-6720-1: Cacti vulnerability
2 April 2024
Cacti could be made to crash if it received specially crafted input.
Releases
Packages
- cacti - web interface for graphing of monitoring systems
Details
Kentaro Kawane discovered that Cacti incorrectly handled user provided
input sent through request parameters to the graph_view.php script.
A remote authenticated attacker could use this issue to perform
SQL injection attacks.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 22.04
-
cacti
-
1.2.19+ds1-2ubuntu1+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.