CVE-2012-3513
Publication date 22 August 2012
Last updated 24 July 2024
Ubuntu priority
munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.
Status
Package | Ubuntu Release | Status |
---|---|---|
munin | ||
Notes
mdeslaur
introduced in http://anonscm.debian.org/gitweb/?p=collab-maint/munin.git;a=commit;h=6a0c4523269977c851a3c63f5add492511c4c55f So only affects 2.x
Patch details
Package | Patch details |
---|---|
munin |
References
Related Ubuntu Security Notices (USN)
- USN-1622-1
- Munin vulnerabilities
- 5 November 2012