Re: CVE-2016-2313 fix wrong

2016-07-29 Thread Emilio Pozuelo Monfort
On 28/07/16 14:59, Matus UHLAR - fantomas wrote: >> On 28/07/16 13:35, Matus UHLAR - fantomas wrote: >>> i believe the fix for CVE-2016-2313 in >>> CVE-2016-2313-authentication-bypass.patch is invalid. > > On 28.07.16 14:26, Emilio Pozuelo Monfort wrote: >> Thanks for the report. I'll look at it

Re: CVE-2016-2313 fix wrong

2016-07-28 Thread Matus UHLAR - fantomas
On 28/07/16 13:35, Matus UHLAR - fantomas wrote: i believe the fix for CVE-2016-2313 in CVE-2016-2313-authentication-bypass.patch is invalid. On 28.07.16 14:26, Emilio Pozuelo Monfort wrote: Thanks for the report. I'll look at it later today. I have posted cacti bug

CVE-2016-2313 fix wrong

2016-07-28 Thread Matus UHLAR - fantomas
Hello, i believe the fix for CVE-2016-2313 in CVE-2016-2313-authentication-bypass.patch is invalid. Quoting the authorization settings: Web Basic Authentication - Authentication is handled by the web server. Users can be added or created automatically on first login if the Template User is