Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [day] [month] [year] [list]
Date: Wed, 22 Feb 2017 20:08:49 +0100
From: Salvatore Bonaccorso <>
To: OSS Security Mailinglist <>
Subject: munin: CVE-2017-6188: Local file write vulnerability

Munin, at least up to 2.0.30 is prone to a local file write
vulnerability, when CGI graphs are enabled. Setting mutliple
'upper_limit' GET parameters allow overwriting any file (accessible by
the user running the cgi-process).

Upstream bug:

MITRE has assigned CVE-2017-6188 for this issue.


Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ