High severity8.1NVD Advisory· Published Dec 12, 2019· Updated Jun 17, 2026
CVE-2019-17358
CVE-2019-17358
Description
Cacti through 1.2.7 is affected by multiple instances of lib/functions.php unsafe deserialization of user-controlled data to populate arrays. An authenticated attacker could use this to influence object data values and control actions taken by Cacti or potentially cause memory corruption in the PHP module.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12<=1.2.7+ 1 more
- (no CPE)range: <=1.2.7
- cpe:2.3:a:cacti:cacti:*:*:*:*:*:*:*:*range: <=1.2.7
- osv-coords7 versionspkg:rpm/opensuse/cacti&distro=openSUSE%20Tumbleweedpkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/opensuse/cacti&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2012pkg:rpm/opensuse/cacti-spine&distro=openSUSE%20Leap%2015.1
< 1.2.18-1.2+ 6 more
- (no CPE)range: < 1.2.18-1.2
- (no CPE)range: < 1.2.9-bp151.4.3.1
- (no CPE)range: < 1.2.9-bp151.4.3.1
- (no CPE)range: < 1.2.9-lp151.3.3.1
- (no CPE)range: < 1.2.11-5.1
- (no CPE)range: < 1.2.11-2.1
- (no CPE)range: < 1.2.9-lp151.3.3.1
- Cacti/Cactidescription
Patches
Vulnerability mechanics
References
14- github.com/Cacti/cacti/blob/79f29cddb5eb05cbaff486cd634285ef1fed9326/lib/functions.phpnvdExploitThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdIssue TrackingThird Party Advisory
- github.com/Cacti/cacti/commit/adf221344359f5b02b8aed43dfb6b33ae5d708c8nvdProductThird Party Advisory
- github.com/Cacti/cacti/issues/3026nvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/12/msg00014.htmlnvdMailing ListThird Party Advisory
- people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-17358.htmlnvdThird Party Advisory
- www.darkmatter.ae/xen1thlabs/nvdNot Applicable
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.htmlnvd
- seclists.org/bugtraq/2020/Jan/25nvd
- security.gentoo.org/glsa/202003-40nvd
- www.debian.org/security/2020/dsa-4604nvd
News mentions
0No linked articles in our index yet.