Deserialization of Untrusted Data in Cacti - CVE-2019-17358
Published: December 16, 2019
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data in lib/functions.php. A remote attacker can pass specially crafted data to the application and execute arbitrary PHP code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Gentoo Linux
Fedora
SUSE Linux
Opensuse
cacti (Debian package)
cacti (Alpine package)
cacti
cacti-spine
SUSE Package Hub for SUSE Linux Enterprise
How to mitigate CVE-2019-17358
cacti (Debian package) - addressed in versions 0.8.8h+ds1-10+deb9u1, 1.2.2+ds1-2+deb10u2
cacti (Alpine package) - addressed in versions 1.2.8-r0, 1.2.10-r0
cacti - addressed in versions 1.2.9-1.el7, 1.2.9-1.el8
cacti-spine - addressed in versions 1.2.9-1.el7, 1.2.9-1.el8
External References
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2019-17358
- https://github.com/Cacti/cacti/blob/79f29cddb5eb05cbaff486cd634285ef1fed9326/lib/functions.php#L3109
- https://github.com/Cacti/cacti/commit/adf221344359f5b02b8aed43dfb6b33ae5d708c8
- https://github.com/Cacti/cacti/issues/3026
- https://lists.debian.org/debian-lts-announce/2019/12/msg00014.html
- https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-17358.html
- https://www.darkmatter.ae/xen1thlabs/
Related Security Bulletins
- Multiple vulnerabilities in Cacti
- Debian update for cacti
- Gentoo update for Cacti
- Deserialization of Untrusted Data in cacti (Alpine package)
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- Fedora EPEL 7 update for cacti, cacti-spine
- Fedora EPEL 8 update for cacti, cacti-spine