ALAS-2014-348

Related Vulnerabilities: CVE-2013-6048   CVE-2013-6359  

The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data. Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name.

ALAS-2014-348


Amazon Linux AMI Security Advisory: ALAS-2014-348
Advisory Release Date: 2014-06-03 15:03 Pacific
Advisory Updated Date: 2014-09-18 00:39 Pacific
Severity: Low

Issue Overview:

The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data.

Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name.


Affected Packages:

munin


Issue Correction:
Run yum update munin to update your system.

New Packages:
noarch:
    munin-async-2.0.20-1.36.amzn1.noarch
    munin-nginx-2.0.20-1.36.amzn1.noarch
    munin-cgi-2.0.20-1.36.amzn1.noarch
    munin-ruby-plugins-2.0.20-1.36.amzn1.noarch
    munin-2.0.20-1.36.amzn1.noarch
    munin-netip-plugins-2.0.20-1.36.amzn1.noarch
    munin-common-2.0.20-1.36.amzn1.noarch
    munin-node-2.0.20-1.36.amzn1.noarch
    munin-java-plugins-2.0.20-1.36.amzn1.noarch

src:
    munin-2.0.20-1.36.amzn1.src