Re: [SECURITY] [DSA 2970-1] cacti security update

2014-06-30 Thread Daniel Thomas Hasbrouck
What am I supposed to Download this ONTO?   PC I'm ON, is a PUBLIC Library
PC.  all of MY USB Flash-Drive are Wiped Clean.  gobble-D-Gook =
incomprehensible Material.


On Sun, Jun 29, 2014 at 10:58 AM, Moritz Muehlenhoff j...@debian.org wrote:

 -BEGIN PGP SIGNED MESSAGE-
 Hash: SHA1

 - -
 Debian Security Advisory DSA-2970-1   secur...@debian.org
 http://www.debian.org/security/Moritz Muehlenhoff
 June 29, 2014  http://www.debian.org/security/faq
 - -

 Package: cacti
 CVE ID : CVE-2014-2326 CVE-2014-2327 CVE-2014-2328 CVE-2014-2708
  CVE-2014-2709 CVE-2014-4002

 Multiple security issues (cross-site scripting, cross-site request
 forgery, SQL injections, missing input sanitising) have been found in
 Cacti, a web frontend for RRDTool.

 For the stable distribution (wheezy), these problems have been fixed in
 version 0.8.8a+dfsg-5+deb7u3.

 For the testing distribution (jessie), these problems have been fixed in
 version 0.8.8b+dfsg-6.

 For the unstable distribution (sid), these problems have been fixed in
 version 0.8.8b+dfsg-6.

 We recommend that you upgrade your cacti packages.

 Further information about Debian Security Advisories, how to apply
 these updates to your system and frequently asked questions can be
 found at: http://www.debian.org/security/

 Mailing list: debian-security-annou...@lists.debian.org
 -BEGIN PGP SIGNATURE-
 Version: GnuPG v1

 iQIcBAEBAgAGBQJTsFOEAAoJEBDCk7bDfE42Nz0QAJB/n4g/zhKu86yaLNqZQBhR
 tT1m51OJ9+2tUI96wnA4ZNUlFqCByCG/CjJGDUWoOGGjD6brZ3xufrLyD0SNickv
 8XB+Wdbv/N6q0joKD96WtYYQcaLNUlhCGyzFmLLa2bo6n9v+85lNDJINCJt2Y3Wy
 B6pyVREhfLGyOdwdrMHn/25yZ7jSc+Cd/o03GyJamZMn6gjY3rh2sNAeCbUIq5Oi
 GFZ9LJvmcHKeSJOm0FFQSFmTrIbLMUb/1/TK2LLAGiHN4fpjkMZsN+vyTgCwgG8y
 7sjhz3QizQ6C/PKGpdmhgmbTgJbGdxO6pyzDGpNxVx+q6eGWP6D5NsbIuNQB9Q/4
 hG+95CJI8orxdyGtu3UVuW3ZjJOi5h2a2oOT1J+dEHhpmrhNXq9aZ+NtCw8RUzuF
 pSH4zNwk078PnYn1vKUBrIZhsrRHB1n4I6FjAm1JpFFWfPzJnPQrE3jxRjNALUqj
 PSyJ3VA54FcHfu/BRj9dqBMFb8zIgOUaO7OOEJ2nsV451IfMHkFtP9uMHSznogaG
 VP6rC8ue/aAyhSEXaBCj+bOLp6UVc9JNXoVL992tKk7EPQsd3Bim7IZnwyhJukAa
 qSlAqstZbAlA+khpcYA6Uq1pFkxlj7rnLIGiskHwMALRGBNmSYUXych9q1qjqxyO
 kfWXzI3r7DFK5U+DqeKs
 =NbC+
 -END PGP SIGNATURE-


 --
 To UNSUBSCRIBE, email to debian-security-announce-requ...@lists.debian.org
 with a subject of unsubscribe. Trouble? Contact
 listmas...@lists.debian.org
 Archive:
 https://lists.debian.org/20140629175803.GA2541@pisco.westfalen.local




Re: [SECURITY] [DSA 2970-1] cacti security update

2014-06-30 Thread Jack
On 30/06/2014 19:21, Daniel Thomas Hasbrouck wrote:
 What am I supposed to Download this ONTO?   PC I'm ON, is a PUBLIC Library
 PC.  all of MY USB Flash-Drive are Wiped Clean.  gobble-D-Gook =
 incomprehensible Material.

The main purpose of this list is to update Debian system administrators
(including users who administer their own machines) about package
updates that have relevance to system security.

If you can't update the software on the machine you are using, then
these notices will be much less useful to you than it will be to others
who can.

Perhaps you should have a chat with the guy at your library who looks
after the PCs.

-- 
Jack.


-- 
To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: https://lists.debian.org/53b1cb28.6010...@jackpot.uk.net