DSA-2610-1 ganglia -- arbitrary script execution

Related Vulnerabilities: CVE-2012-3448  

Insufficient input sanitization in Ganglia, a web based monitoring system, could lead to remote PHP script execution with permissions of the user running the web server. For the stable distribution (squeeze), this problem has been fixed in version 3.1.7-1+squeeze1. For the testing distribution (wheezy), this problem has been fixed in version 3.3.8-1. For the unstable distribution (sid), this problem has been fixed in version 3.3.8-1. We recommend that you upgrade your ganglia packages.

Debian Security Advisory

DSA-2610-1 ganglia -- arbitrary script execution

Date Reported:
21 Jan 2013
Affected Packages:
ganglia
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 683584.
In Mitre's CVE dictionary: CVE-2012-3448.
More information:

Insufficient input sanitization in Ganglia, a web based monitoring system, could lead to remote PHP script execution with permissions of the user running the web server.

For the stable distribution (squeeze), this problem has been fixed in version 3.1.7-1+squeeze1.

For the testing distribution (wheezy), this problem has been fixed in version 3.3.8-1.

For the unstable distribution (sid), this problem has been fixed in version 3.3.8-1.

We recommend that you upgrade your ganglia packages.