|
Message-ID: <56C09A15.8060108@debian.org>
Date: Sun, 14 Feb 2016 16:15:33 +0100
From: Paul Gevers <elbrus@...ian.org>
To: oss-security@...ts.openwall.com
Subject: Re: CVE Request: cacti: Authentication using web authentication as a
user, not in the,cacti database allows complete access
[Sorry for breaking the thread, I don't have access to the original mail]
Just a note regarding the proposed patch for CVE-2016-2313.
As I already noted in the original upstream bug report¹, I am not
convinced that the "bug" was not (accidental) mis-configuration. I am
convinced that the proposed patch is wrong and told upstream about it.
The patch prevents features of cacti that allow an authenticated user
who is not in the cacti database to get *specified* access to cacti. I
don't know how many setups are using this feature, but the patch is a
regression for those setups. The patch does not change anything in the
configuration tab in the UI, so this at least leads to a confusing
situation.
Paul
¹ http://bugs.cacti.net/view.php?id=2656
Download attachment "signature.asc" of type "application/pgp-signature" (474 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.