[focal] cacti needs a merge from 1.2.4+ds1-2ubuntu3 to 1.2.9+ds1-1

Bug #1863739 reported by Rafael David Tinoco
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
cacti (Ubuntu)
Fix Released
Medium
Rafael David Tinoco

Bug Description

[focal] cacti needs a merge from 1.2.4+ds1-2ubuntu3 to 1.2.9+ds1-1

mysql-server-8 patches for cacti did not make into Debian yet as mysql-server in Debian is still being upgraded. Since cacti is way behind now, I'll merge and keep the delta for now.

Related branches

Changed in cacti (Ubuntu):
status: New → Triaged
status: Triaged → In Progress
importance: Undecided → Medium
assignee: nobody → Rafael David Tinoco (rafaeldtinoco)
Revision history for this message
Rafael David Tinoco (rafaeldtinoco) wrote :
Revision history for this message
Graham Inggs (ginggs) wrote :

I believe this change can be dropped:
Replace php-php-gettext dependency in order to fix translations

then php-gettext can be removed from Ubuntu, see Debian bug #851771

Revision history for this message
Graham Inggs (ginggs) wrote :

cacti (1.2.6+ds1-2) unstable; urgency=medium

  * Translations were broken since 1.2.4+ds1-1. Import upstream solution
    enabling the use of php-phpmyadmin-motranslator.

Revision history for this message
Rafael David Tinoco (rafaeldtinoco) wrote :

Alright @ginggs, based on the Debian bug and your input I have dropped that commit from the merge request, will submit resulting package back to PPA so we have an updated build to test. Thanks for the feedback.

Revision history for this message
Graham Inggs (ginggs) wrote :

I did a fresh install of cacti 1.2.4+ds1-2ubuntu3 on a machine running focal and confirmed that I could log in to the web ui.
I added your PPA and upgraded to 1.2.9+ds1-1ubuntu1, the web interface reflected the upgrade to 1.2.9.
I was able to remove the php-php-gettext package.
I rebooted and everything was still fine.

I think the only change needed is to mention in the changelog that the 'Replace php-php-gettext dependency' change was dropped.

Revision history for this message
Rafael David Tinoco (rafaeldtinoco) wrote :

Thats awesome @ginggs, thanks for reviewing it and, indeed, I'll mention that in the changelog.

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package cacti - 1.2.9+ds1-1ubuntu1

---------------
cacti (1.2.9+ds1-1ubuntu1) focal; urgency=medium

  * Merge with Debian unstable (LP: #1863739). Remaining changes:
    - General installing instructions update for NO_AUTO_CREATE_USER.
    - Use new dbconfig "dbc_authplugin" variable to mitigate MySQL 8 issues.
  * Dropped changes [upstream]:
    - MySQL 8 change needs: NO_AUTO_CREATE_USER and grouping keyword.
  * Dropped changes [debian]:
    - Replace php-php-gettext dependency in order to fix translations
      (LP #1844070)

cacti (1.2.9+ds1-1) unstable; urgency=medium

  * New upstream version 1.2.9+ds1
    CVE-2020-7106 Remote Code Execution (by privileged users) via shell
    metacharacters in the Performance Boost Debug Log field of
    poller_automation.php. (Closes: #949996)
    CVE-2020-7237 Stored XSS in data_sources.php,
    color_templates_item.php, graphs.php, graph_items.php,
    lib/api_automation.php, user_admin.php, and user_group_admin.php, as
    demonstrated by the description parameter in data_sources.php (Closes:
    #949997)

cacti (1.2.8+ds1-1) unstable; urgency=medium

  * New upstream version 1.2.8+ds1
    CVE-2019-17357 When viewing graphs, some input variables are not
    properly checked (SQL injection possible) (Closes: #947374)
    CVE-2019-17358 When deserializating data, ensure basic sanitization
    has been performed (Closes: #947375)

cacti (1.2.7+ds1-1) unstable; urgency=medium

  * New upstream version 1.2.7+ds1
    CVE-2019-16723 Security issue allows to view all graphs (Closes:
    #941036)
  * Refresh and drop patches to match upstream

cacti (1.2.6+ds1-3) unstable; urgency=medium

  * Add 0001-Resolving-Issue-2984.patch to fix CI error

cacti (1.2.6+ds1-2) unstable; urgency=medium

  [ Paul Gevers]
  * Fix autopkgtest regression with 0001-Resolving-Issue-2899.patch from
    upstream
  * Apache skipped the php section in apache.conf since PHP 7 (Closes:
    #934898)
  * Translations were broken since 1.2.4+ds1-1. Import upstream solution
    enabling the use of php-phpmyadmin-motranslator.

  [ Rafael David Tinoco ]
  * Prepare sql commands for MySQL 8 (See: #933683)

 -- Rafael David Tinoco <email address hidden> Tue, 18 Feb 2020 13:28:26 +0000

Changed in cacti (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.