Date: Wed, 22 Feb 2017 20:08:49 +0100 From: Salvatore Bonaccorso <carnil@...ian.org> To: OSS Security Mailinglist <oss-security@...ts.openwall.com> Subject: munin: CVE-2017-6188: Local file write vulnerability Munin, at least up to 2.0.30 is prone to a local file write vulnerability, when CGI graphs are enabled. Setting mutliple 'upper_limit' GET parameters allow overwriting any file (accessible by the user running the cgi-process). Upstream bug: https://github.com/munin-monitoring/munin/issues/721 MITRE has assigned CVE-2017-6188 for this issue. Regards, Salvatore
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ