Debian Security Advisory
DSA-2610-1 ganglia -- arbitrary script execution
- Date Reported:
- 21 Jan 2013
- Affected Packages:
- Security database references:
- In the Debian bugtracking system: Bug 683584.
In Mitre's CVE dictionary: CVE-2012-3448.
- More information:
Insufficient input sanitization in Ganglia, a web based monitoring system, could lead to remote PHP script execution with permissions of the user running the web server.
For the stable distribution (squeeze), this problem has been fixed in version 3.1.7-1+squeeze1.
For the testing distribution (wheezy), this problem has been fixed in version 3.3.8-1.
For the unstable distribution (sid), this problem has been fixed in version 3.3.8-1.
We recommend that you upgrade your ganglia packages.