CVE-2007-3113
published 2007-06-07CVE-2007-3113: Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1)…
PriorityP419medium6.8CVSS 2.0
AVNACLAuSCNINAC
EPSS
2.74%
84.6th percentile
Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | >= 0 < 0.8.6j-1.1 | 0.8.6j-1.1 |
| cacti | cacti | >= 0 < 0.8.6j-1.1 | 0.8.6j-1.1 |
| cacti | cacti | >= 0 < 0.8.6j-1.1 | 0.8.6j-1.1 |
| cacti | cacti | >= 0 < 0.8.6j-1.1 | 0.8.6j-1.1 |
| debian | cacti | < cacti 0.8.6j-1.1 (bookworm) | cacti 0.8.6j-1.1 (bookworm) |
| the_cacti_group | cacti | <= 0.8.6i | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2007-3112: cacti - graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote auth...
vendor_debian·2007·CVSS 7.8
CVE-2007-3112 [HIGH] CVE-2007-3112: cacti - graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote auth...
graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_start or (2) graph_end parameter, different vectors than CVE-2007-3113.
Scope: local
bookworm: resolved (fixed in 0.8.6j-1.1)
bullseye: resolved (fixed in 0.8.6j-1.1)
forky: resolved (fixed in 0.8.6j-1.1)
sid: resolved (fixed in 0.8.6j-1.1)
trixie: resolved (fixed in 0.8.6j-1.1)
Debian
CVE-2007-3113: cacti - Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to ...
vendor_debian·2007·CVSS 7.8
CVE-2007-3113 [HIGH] CVE-2007-3113: cacti - Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to ...
Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112.
Scope: local
bookworm: resolved (fixed in 0.8.6j-1.1)
bullseye: resolved (fixed in 0.8.6j-1.1)
forky: resolved (fixed in 0.8.6j-1.1)
sid: resolved (fixed in 0.8.6j-1.1)
trixie: resolved (fixed in 0.8.6j-1.1)
GHSA
GHSA-36fx-rf6c-vc8x: Cacti 0
ghsa_unreviewed·2022-05-01·CVSS 7.8
CVE-2007-3113 [HIGH] GHSA-36fx-rf6c-vc8x: Cacti 0
Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112.
GHSA
GHSA-3wj7-jcqx-7j5f: graph_image
ghsa_unreviewed·2022-05-01·CVSS 6.8
CVE-2007-3112 [MEDIUM] GHSA-3wj7-jcqx-7j5f: graph_image
graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_start or (2) graph_end parameter, different vectors than CVE-2007-3113.
OSV
CVE-2007-3112: graph_image
osv·2007-06-07·CVSS 7.8
CVE-2007-3112 [HIGH] CVE-2007-3112: graph_image
graph_image.php in Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_start or (2) graph_end parameter, different vectors than CVE-2007-3113.
OSV
CVE-2007-3113: Cacti 0
osv·2007-06-07·CVSS 7.8
CVE-2007-3113 [HIGH] CVE-2007-3113: Cacti 0
Cacti 0.8.6i, and possibly other versions, allows remote authenticated users to cause a denial of service (CPU consumption) via a large value of the (1) graph_height or (2) graph_width parameter, different vectors than CVE-2007-3112.
No detection rules found.
No public exploits indexed.
http://bugs.cacti.net/view.php?id=955http://fedoranews.org/updates/FEDORA-2007-219.shtmlhttp://mdessus.free.fr/?p=15http://osvdb.org/37019http://secunia.com/advisories/25557http://secunia.com/advisories/26872http://svn.cacti.net/cgi-bin/viewcvs.cgi/branches/BRANCH_0_8_6/cacti/graph_image.php?rev=3956&r1=3898&r2=3956http://www.mandriva.com/security/advisories?name=MDKSA-2007:184https://bugzilla.redhat.com/show_bug.cgi?id=243592https://exchange.xforce.ibmcloud.com/vulnerabilities/34747http://bugs.cacti.net/view.php?id=955http://fedoranews.org/updates/FEDORA-2007-219.shtmlhttp://mdessus.free.fr/?p=15http://osvdb.org/37019http://secunia.com/advisories/25557http://secunia.com/advisories/26872http://svn.cacti.net/cgi-bin/viewcvs.cgi/branches/BRANCH_0_8_6/cacti/graph_image.php?rev=3956&r1=3898&r2=3956http://www.mandriva.com/security/advisories?name=MDKSA-2007:184https://bugzilla.redhat.com/show_bug.cgi?id=243592https://exchange.xforce.ibmcloud.com/vulnerabilities/34747
2007-06-07
Published