CVE-2019-17358
Summary
| CVE | CVE-2019-17358 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-12 14:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module. |
Risk And Classification
Problem Types: CWE-787 | CWE-502
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cacti | Cacti | All | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Opensuse | Leap | 42.3 | All | All | All |
| Operating System | Opensuse | Leap | 42.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bugtraq: [SECURITY] [DSA 4604-1] cacti security update | BUGTRAQ | seclists.org | |
| Debian -- Security Information -- DSA-4604-1 cacti | DEBIAN | www.debian.org | |
| [security-announce] openSUSE-SU-2020:0284-1: important: Security update | SUSE | lists.opensuse.org | |
| Resoving Issue #3026 · Cacti/cacti@adf2213 · GitHub | MISC | github.com | Product, Third Party Advisory |
| When deserializating data, ensure basic sanitization has been performed · Issue #3026 · Cacti/cacti · GitHub | MISC | github.com | Issue Tracking, Third Party Advisory |
| Bug 1158992 – VUL-0: CVE-2019-17358: cacti: Unsafe deserialization in sanitize_unserialize_selected_items | MISC | bugzilla.suse.com | Issue Tracking, Third Party Advisory |
| [security-announce] openSUSE-SU-2020:0565-1: important: Security update | SUSE | lists.opensuse.org | |
| CVE-2019-17358 in Ubuntu | MISC | people.canonical.com | Third Party Advisory |
| [SECURITY] [DLA 2032-1] cacti security update | MISC | lists.debian.org | Mailing List, Third Party Advisory |
| [security-announce] openSUSE-SU-2020:0558-1: important: Security update | SUSE | lists.opensuse.org | |
| DarkMatter - Smart and Safe Digital | | MISC | www.darkmatter.ae | Not Applicable |
| Cacti: Multiple vulnerabilities (GLSA 202003-40) — Gentoo security | GENTOO | security.gentoo.org | |
| [security-announce] openSUSE-SU-2020:0272-1: important: Security update | SUSE | lists.opensuse.org | |
| cacti/functions.php at 79f29cddb5eb05cbaff486cd634285ef1fed9326 · Cacti/cacti · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.