Bug#833420: cacti: Incomplete fix for CVE-2016-2313

2016-08-04 Thread Salvatore Bonaccorso
Control: tags -1 - security Remvoving the security tag. If I understand it correctly, the incomplete fix has not directly security implication, but considered a regression in functionality (guests cannot login anymore). So guess this does not need a separate CVE for the incomplete fix applied. Re

Bug#833420: cacti: Incomplete fix for CVE-2016-2313

2016-08-03 Thread Salvatore Bonaccorso
Source: cacti Version: 0.8.8h+ds1-4 Severity: important Tags: security upstream Forwarded: http://bugs.cacti.net/view.php?id=2697 Hi Paul, As originally reported to [0,1] the fix for CVE-2016-2313 seems incomplete. This affects the unstable version and the version which is waiting in jessie-propo