CVE-2024-34340

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-34340
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-34340.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-34340
Aliases
  • GHSA-37x7-mfjv-mm7m
Related
Published
2024-05-14T15:38:39Z
Modified
2024-09-11T05:12:05.533848Z
Summary
[none]
Details

Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls compat_password_hash when users set their password. compat_password_hash use password_hash if there is it, else use md5. When verifying password, it calls compat_password_verify. In compat_password_verify, password_verify is called if there is it, else use md5. password_verify and password_hash are supported on PHP < 5.5.0, following PHP manual. The vulnerability is in compat_password_verify. Md5-hashed user input is compared with correct password in database by $md5 == $hash. It is a loose comparison, not ===. It is a type juggling vulnerability. Version 1.2.27 contains a patch for the issue.

References

Affected packages

Debian:11 / cacti

Package

Name
cacti
Purl
pkg:deb/debian/cacti?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.16+ds1-2+deb11u4

Affected versions

1.*

1.2.16+ds1-2
1.2.16+ds1-2+deb11u1
1.2.16+ds1-2+deb11u2
1.2.16+ds1-2+deb11u3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / cacti

Package

Name
cacti
Purl
pkg:deb/debian/cacti?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.24+ds1-1+deb12u3

Affected versions

1.*

1.2.24+ds1-1
1.2.24+ds1-1+deb12u1
1.2.24+ds1-1+deb12u2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / cacti

Package

Name
cacti
Purl
pkg:deb/debian/cacti?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.27+ds1-1

Affected versions

1.*

1.2.24+ds1-1
1.2.25+ds1-1
1.2.25+ds1-2
1.2.26+ds1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}