- Package:
- cacti
- Source:
- cacti
- Submitter:
- Mark Brugnoli-Vinten
- Date:
- 2022-07-14 15:36:08 UTC
- Severity:
- normal
- Blocked By:
-
Bug Title 1009952 7
depends needlessly on nodejs normal stable about 4 years ago
1009953 7
depends needlessly on nodejs normal stable about 4 years ago
839961 9
libjs-d3: please package new upstream release wishlist stable testing unstable about 4 years ago
1009950 7
depends needlessly on nodejs normal stable about 4 years ago
1009949 6
depends needlessly on nodejs normal stable about 4 years ago
1009951 7
depends needlessly on nodejs normal stable testing about 4 years ago
It has come to light that there are various packages which Cacti utilises that are not up to date. As such, these are causing issues with users not seeing the results that are expected with things like Graphs, Charts, etc. A specific issue was found where a user was complaining that a Cacti third party plugin was not working properly and it appears that their Chart.js file was symlink'd to a v1.0.2 version provided by a package that is woefully outdated. The following are some of the dependancies that seem to be out of date: 1.1.38 — libjs-C3: 0.4.11+dfsg-2 < 0.4.21 libjs-D3: 3.5.17-2 < 4.13.0 libjs-chartjs: 1.0.2 < 2.7.2 For the upcoming 1.2.0 release, these are updated again to the following versions: 1.2.0 — libjs-C3: 0.4.11+dfsg-2 < 0.6.8 libjs-D3: 3.5.17-2 < 5.7.0 libjs-chartjs: 1.0.2 < 2.7.3 The other package dependancies should probably also be checked since they could also cause issues. Thanks, Mark.
Dear Mark, Thanks for filing this bug. Apart from the issues we noticed with Chart.js, do you know if Cacti is using features from the versions of C3 and D3 shipped by Cacti that are lacking in the versions in Debian? Do you know if the issue with Chart.js is already present in 1.1.38? Paul
I believe the issue is present in previous versions since the intropage plugin can be used on earlier versions. I would have to double check what core features or any of our plugins use those three items but given that a plugin can come from anywhere and developers will most likely build against Cacti from GitHub sources rather than packages, this could affect any number of plugins that are out there that I wouldn’t know about. Obviously minor variations in package versions sometimes happen but as long as they are close to the one we have it will likely be only minor bugs that are unlikely to affect us. Major ones will be an issue since that can be whole functionality missing or changed. Mark
We believe that the bug you reported is fixed in the latest version of
cacti, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 913385@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Paul Gevers <elbrus@debian.org> (supplier of updated cacti package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 14 Apr 2022 10:16:39 +0200
Source: cacti
Architecture: source
Version: 1.2.20+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Cacti Maintainer <pkg-cacti-maint@lists.alioth.debian.org>
Changed-By: Paul Gevers <elbrus@debian.org>
Closes: 913385 1008693
Changes:
cacti (1.2.20+ds1-1) unstable; urgency=medium
.
* New upstream version 1.2.20+ds1
CVE-2022-0730: Under certain ldap conditions, Cacti authentication can
be bypassed with certain credential types. (Closes: #1008693)
* d/copyright: update
* strip away and replace some of the new midwinter theme like we do for
other themes
* Refresh patches and drop those that are part of 1.2.20
* cacti.links: drop dejavu links as cacti now finds system fonts by
itself
* Replace dependency on libjs-d3 by node-d3 (Closes: #913385)
* Replace broken package (Upstream bug: #4685)
* Fix multiple issues with new cli scripts (detected by test suite
failure)
Checksums-Sha1:
5a913ba08fed21e50f03ca3d6799e33708dc4ff2 2140 cacti_1.2.20+ds1-1.dsc
053ff66d2a0fff9fdd9351c900b0af9403732a6e 23953741 cacti_1.2.20+ds1.orig-docs-source.tar.gz
2e12001831b697430f3d53f08e9dcc5155151230 8411583 cacti_1.2.20+ds1.orig.tar.gz
cc139781096ac3d9fad87de00fd4083f1354a0ca 912216 cacti_1.2.20+ds1-1.debian.tar.xz
Checksums-Sha256:
73d2584ed874a5712e709d8309a11eeb5ccf6cd12d208d0c0a4984710b8d434b 2140 cacti_1.2.20+ds1-1.dsc
893a9d05b6eb331468e28eb2620f17f37314239419cf5c64c4ce47d7463aa2b6 23953741 cacti_1.2.20+ds1.orig-docs-source.tar.gz
635e7be19f5d5c7dcc44e64675ccb79991dc34bcc8723ac541d74e4da676a0ed 8411583 cacti_1.2.20+ds1.orig.tar.gz
287b0f59cd002ca46464681e21d94ba69ec58e27657bc1162336ea9ceff9d9c7 912216 cacti_1.2.20+ds1-1.debian.tar.xz
Files:
a25c4b99da6b1208abe01a28bf72a725 2140 web optional cacti_1.2.20+ds1-1.dsc
b6a18dc7535b4903985dd21ba921b174 23953741 web optional cacti_1.2.20+ds1.orig-docs-source.tar.gz
fba23aed1e500833d297d8a0e4c95653 8411583 web optional cacti_1.2.20+ds1.orig.tar.gz
c15261378b897907239d76491193e357 912216 web optional cacti_1.2.20+ds1-1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQEzBAEBCAAdFiEEWLZtSHNr6TsFLeZynFyZ6wW9dQoFAmJX4SMACgkQnFyZ6wW9
dQq3CggAnHJgIakwplWDUB/YrxXkZkroHKEMWEjs+/U+rZQC1V2NS3T0U3ZjTAt8
oHjg82VOkycOcQqwuYWlhPcVinikQLb6Dq08BcOTvOs4cIkJEX2d3YTypAigTxHh
OBgHG0QwK9UQHphwptT2vi+VH8i1b9XR7orGuTHfiRg1Zv3WbSxUZfwpPBoUMK60
UFBaz4VfKBnVE7Vs+ftCEpj/DJGXsnGxxv+AgCrNZy16GdfHpslFG+v8anRo9KK6
2xPKAaehNP1XDSx1gh8fecCcmLEy/popoVxhXgIYxC1yQWXT+n1++D5LieoqVYxL
ury+tCsLVeH8C1gqyOSsFl1feS/bDg==
=BB3G
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of cacti, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 913385@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Paul Gevers <elbrus@debian.org> (supplier of updated cacti package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Thu, 14 Jul 2022 17:05:21 +0200 Source: cacti Architecture: source Version: 1.2.21+ds1-1 Distribution: unstable Urgency: medium Maintainer: Cacti Maintainer <pkg-cacti-maint@lists.alioth.debian.org> Changed-By: Paul Gevers <elbrus@debian.org> Closes: 913385 979176 Changes: cacti (1.2.21+ds1-1) unstable; urgency=medium . * New upstream version 1.2.21+ds1 * Refresh and update old patch stack * Replace dependency on libjs-d3 by node-d3 (Closes: #913385) * README.Debian: reorder paragraphs (Closes: #979176) Checksums-Sha1: 133dd679fb49cb9d4d27166de24d26c84c12200a 2253 cacti_1.2.21+ds1-1.dsc 8127c48449232943d57fef397d80431ee820a41f 24204538 cacti_1.2.21+ds1.orig-docs-source.tar.gz 4ab1321df10a603abca74c1bc77ed82f8b64bf17 8240399 cacti_1.2.21+ds1.orig.tar.gz f9e2d7d59a678377f491ce6fc4f834054dbe940d 55256 cacti_1.2.21+ds1-1.debian.tar.xz Checksums-Sha256: 55306fce89bd281cac1d05ea31f34f97dad1cd4fe8492ea36e1ff8c278f8e39a 2253 cacti_1.2.21+ds1-1.dsc 2b42d171dfab0dce13021f41115c85e201418ae5e30cdf14362f4fe2fb4a85d4 24204538 cacti_1.2.21+ds1.orig-docs-source.tar.gz 189a2558b21f18d5ac3930ac47e831edea210bb1da3224794c51b43d81433d25 8240399 cacti_1.2.21+ds1.orig.tar.gz ea0eea767793e2ada8ebcc4db43ddf0e873f5fbf3ee6b994eb19f7f419b547b6 55256 cacti_1.2.21+ds1-1.debian.tar.xz Files: 11c15e84820f3f79d934c7eb02798710 2253 web optional cacti_1.2.21+ds1-1.dsc b0a9406693a458d6f74e21876a75b037 24204538 web optional cacti_1.2.21+ds1.orig-docs-source.tar.gz 6377001dc81910556499779b22616d28 8240399 web optional cacti_1.2.21+ds1.orig.tar.gz 8f70e17b4d6f528ba7e42ac743b63f77 55256 web optional cacti_1.2.21+ds1-1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQEzBAEBCAAdFiEEWLZtSHNr6TsFLeZynFyZ6wW9dQoFAmLQMpYACgkQnFyZ6wW9 dQoyogf9EUQLvFEHvs3M4yLZfJNmcJELXSCNTiLMK2lOKKnwBBf9gnaLQZHg9xCo Vz+EWgDoRLycOFlMnK8tJ7kcqJMSizpHBTOtSz260u5plrPA+PK+PfeTPByR/Fbp dI8S9c8NvXqmJWc1MoMoQd1LR0yGlIn8BtdjXEc1F/lX6c51Tdgn0L6sh7BtI7Cw siipncI7xTGHSvogDWKxfVBjOrfF2auUyVCmhoY5cVwyAJg88UT+wbSSj8zL0AwV QzoA257Cybw9qxc5BHBqFDTUHeCmIsNNeU5mmXZjNFAkzZqLcdXgLwLH+hyCObbS h/x8p6k+ilJyf8S1JaTH7qPlUEOIMg== =2Sfb -----END PGP SIGNATURE-----