Debian Security Advisory
DSA-3794-1 munin -- security update
- Date Reported:
- 25 Feb 2017
- Affected Packages:
- munin
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 855705.
In Mitre's CVE dictionary: CVE-2017-6188. - More information:
-
Stevie Trujillo discovered a local file write vulnerability in munin, a network-wide graphing framework, when CGI graphs are enabled. GET parameters are not properly handled, allowing to inject options into munin-cgi-graph and overwriting any file accessible by the user running the cgi-process.
For the stable distribution (jessie), this problem has been fixed in version 2.0.25-1+deb8u1.
We recommend that you upgrade your munin packages.