Bug 585401 (BONSAI-2010-0104, CVE-2010-1431) - CVE-2010-1431 cacti: SQL injection vulnerability (BONSAI-2010-0104)
Summary: CVE-2010-1431 cacti: SQL injection vulnerability (BONSAI-2010-0104)
Alias: BONSAI-2010-0104, CVE-2010-1431
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: 541684 585207 585402
TreeView+ depends on / blocked
Reported: 2010-04-23 21:26 UTC by Vincent Danen
Modified: 2019-09-29 12:36 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Last Closed: 2010-12-21 22:45:24 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2010:0635 0 normal SHIPPED_LIVE Important: Red Hat High Performance Computing (HPC) Solution 5.5 2010-08-20 02:42:21 UTC

Description Vincent Danen 2010-04-23 21:26:14 UTC
An SQL injection vulnerability was reported in cacti [1].  Input passed via the 'export_item_id' parameter to the templates_export.php script is not properly sanitized prior to being used in an SQL query.  Upstream has provided a patch to correct this issue [2].

[1] http://seclists.org/fulldisclosure/2010/Apr/272
[2] http://www.cacti.net/downloads/patches/0.8.7e/sql_injection_template_export.patch

Comment 1 Vincent Danen 2010-04-23 21:27:50 UTC
Created cacti tracking bugs for this issue

Affects: fedora-all [bug 585402]

Comment 2 Vincent Danen 2010-04-26 19:27:21 UTC
bug 585207 has addressed this in Fedora and EPEL.

Comment 3 Vincent Danen 2010-04-26 19:52:47 UTC
This has been assigned CVE-2010-1431.

Comment 4 Tomas Hoger 2010-06-29 09:05:37 UTC
Direct link to BONSAI-2010-0104 advisory:


Comment 5 errata-xmlrpc 2010-08-20 02:42:32 UTC
This issue has been addressed in following products:

  Red Hat HPC Solution for RHEL 5

Via RHSA-2010:0635 https://rhn.redhat.com/errata/RHSA-2010-0635.html

Note You need to log in before you can comment on or make changes to this bug.