oss-sec mailing list archives

munin: CVE-2017-6188: Local file write vulnerability


From: Salvatore Bonaccorso <carnil () debian org>
Date: Wed, 22 Feb 2017 20:08:49 +0100

Munin, at least up to 2.0.30 is prone to a local file write
vulnerability, when CGI graphs are enabled. Setting mutliple
'upper_limit' GET parameters allow overwriting any file (accessible by
the user running the cgi-process).

Upstream bug: https://github.com/munin-monitoring/munin/issues/721

MITRE has assigned CVE-2017-6188 for this issue.

Regards,
Salvatore


Current thread: