Re: [SECURITY] [DLA 2069-1] cacti security update

2020-01-27 Thread Chris Lamb
Hi Hugo et al., > > Package: cacti > > Version: 0.8.8b+dfsg-8+deb8u9 > > CVE ID : CVE-2020-7106 […] > a followup patch was just published for CVE-2020-7106[0]. If you want to > release a regression update, I'd recommend to wait a few days. I would not > be surprised to see

Re: [SECURITY] [DLA 2069-1] cacti security update

2020-01-22 Thread Hugo Lefeuvre
Hi Chris, > > a followup patch was just published for CVE-2020-7106[0]. If you want to > > release a regression update, I'd recommend to wait a few days. > > Thanks for spotting this and for your sage advice — I have added it to my > calendar to recheck this shortly and will investigate and follo

Re: [SECURITY] [DLA 2069-1] cacti security update

2020-01-22 Thread Dylan Aïssi
Hi Chris, Le mer. 22 janv. 2020 à 12:11, Chris Lamb a écrit : > To prevent duplicated work, Dylan, just checking that you are either > aware of this thread and its context? It was, of course, my mistake > for not commenting and/or claiming it in dla-needed.txt. No problem, feel free to claim it

Re: [SECURITY] [DLA 2069-1] cacti security update

2020-01-22 Thread Chris Lamb
[adding Dylan Aïssi to CC] Chris Lamb wrote: > > a followup patch was just published for CVE-2020-7106[0]. If you want to > > release a regression update, I'd recommend to wait a few days. > > Thanks for spotting this and for your sage advice — I have added it to my > calendar to recheck this s

Re: [SECURITY] [DLA 2069-1] cacti security update

2020-01-19 Thread Chris Lamb
Hi Hugo, > a followup patch was just published for CVE-2020-7106[0]. If you want to > release a regression update, I'd recommend to wait a few days. Thanks for spotting this and for your sage advice — I have added it to my calendar to recheck this shortly and will investigate and follow-up then.

Re: [SECURITY] [DLA 2069-1] cacti security update

2020-01-19 Thread Hugo Lefeuvre
Hi Chris, On Sat, Jan 18, 2020 at 02:01:07PM +, Chris Lamb wrote: > Package: cacti > Version: 0.8.8b+dfsg-8+deb8u9 > CVE ID : CVE-2020-7106 > > It was discovered that there were a number of cross-site scripting > vulnerabilities in cacti, a web interface for monitoring

Re: cacti security update

2014-07-18 Thread Stefan Gundel
Am 15.07.2014 um 09:22 schrieb Paul Gevers : > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Package: cacti > Version: 0.8.7g-1+squeeze4 > CVE ID : CVE-2014-2326 CVE-2014-2327 CVE-2014-2328 > CVE-2014-2708 CVE-2014-2709 CVE-2014-4002 > Debian Bug

Re: Fwd: cacti security update

2014-07-14 Thread Alexander Wirt
On Tue, 15 Jul 2014, Moritz Muehlenhoff wrote: > On Mon, Jul 14, 2014 at 09:20:54PM +0200, Paul Gevers wrote: > > Hi all, > > > > On 5 July, I sent the attached security update to the announce list. It > > seems to have never reached that list. Could somebody enlighten me and > > tell me what I d

Re: Fwd: cacti security update

2014-07-14 Thread Moritz Muehlenhoff
On Mon, Jul 14, 2014 at 09:20:54PM +0200, Paul Gevers wrote: > Hi all, > > On 5 July, I sent the attached security update to the announce list. It > seems to have never reached that list. Could somebody enlighten me and > tell me what I did wrong? Only list masters can investigate this. Please se

Fwd: cacti security update

2014-07-14 Thread Paul Gevers
Hi all, On 5 July, I sent the attached security update to the announce list. It seems to have never reached that list. Could somebody enlighten me and tell me what I did wrong? Paul --- Begin Message --- Package: cacti Version: 0.8.7g-1+squeeze4 CVE ID : CVE-2014-2326 CVE-