LWN.net Logo

munin: multiple vulnerabilities

Package(s):munin CVE #(s):CVE-2012-2103 CVE-2012-3513
Created:November 5, 2012 Updated:November 7, 2012
Description: From the Ubuntu advisory:

It was discovered that the Munin qmailscan plugin incorrectly handled temporary files. A local attacker could use this issue to possibly overwrite arbitrary files. This issue only affected Ubuntu 10.04 LTS, Ubuntu 11.10, and Ubuntu 12.04 LTS. (CVE-2012-2103)

It was discovered that Munin incorrectly handled specifying an alternate configuration file. A remote attacker could possibly use this issue to execute arbitrary code with the privileges of the web server. This issue only affected Ubuntu 12.10. (CVE-2012-3513)

Alerts:
Ubuntu USN-1622-1 2012-11-05
Mageia MGASA-2012-0358 2012-12-11
Mandriva MDVSA-2013:105 2013-04-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds