oss-sec mailing list archives
Re: CVE Request: cacti: Authentication using web authentication as a user, not in the,cacti database allows complete access
From: Paul Gevers <elbrus () debian org>
Date: Sun, 14 Feb 2016 16:15:33 +0100
[Sorry for breaking the thread, I don't have access to the original mail] Just a note regarding the proposed patch for CVE-2016-2313. As I already noted in the original upstream bug report¹, I am not convinced that the "bug" was not (accidental) mis-configuration. I am convinced that the proposed patch is wrong and told upstream about it. The patch prevents features of cacti that allow an authenticated user who is not in the cacti database to get *specified* access to cacti. I don't know how many setups are using this feature, but the patch is a regression for those setups. The patch does not change anything in the configuration tab in the UI, so this at least leads to a confusing situation. Paul ¹ http://bugs.cacti.net/view.php?id=2656
Attachment:
signature.asc
Description: OpenPGP digital signature
Current thread:
- Re: CVE Request: cacti: Authentication using web authentication as a user, not in the,cacti database allows complete access Paul Gevers (Feb 14)