Ubuntu alert USN-3215-2 (munin)
From: | Marc Deslauriers <marc.deslauriers@canonical.com> | |
To: | ubuntu-security-announce@lists.ubuntu.com | |
Subject: | [USN-3215-2] Munin regression | |
Date: | Fri, 3 Mar 2017 10:35:37 -0500 | |
Message-ID: | <80577ed1-7844-c71a-8236-a49902f5dae6@canonical.com> |
========================================================================== Ubuntu Security Notice USN-3215-2 March 03, 2017 munin regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: USN-3215-1 introduced a regression in Munin. Software Description: - munin: Network-wide graphing framework Details: USN-3215-1 fixed a vulnerability in Munin. The upstream patch caused a regression leading to errors being appended to the log file. This update fixes the problem. Original advisory details: It was discovered that Munin incorrectly handled CGI graphs. A remote attacker could use this issue to overwrite arbitrary files as the www-data user. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: munin 2.0.19-3ubuntu0.3 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-3215-2 http://www.ubuntu.com/usn/usn-3215-1 https://launchpad.net/bugs/1669764 Package Information: https://launchpad.net/ubuntu/+source/munin/2.0.19-3ubuntu0.3 -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security...