DSA-3794-1 munin -- security update

Related Vulnerabilities: CVE-2017-6188  

Stevie Trujillo discovered a local file write vulnerability in munin, a network-wide graphing framework, when CGI graphs are enabled. GET parameters are not properly handled, allowing to inject options into munin-cgi-graph and overwriting any file accessible by the user running the cgi-process. For the stable distribution (jessie), this problem has been fixed in version 2.0.25-1+deb8u1. We recommend that you upgrade your munin packages.

Debian Security Advisory

DSA-3794-1 munin -- security update

Date Reported:
25 Feb 2017
Affected Packages:
munin
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 855705.
In Mitre's CVE dictionary: CVE-2017-6188.
More information:

Stevie Trujillo discovered a local file write vulnerability in munin, a network-wide graphing framework, when CGI graphs are enabled. GET parameters are not properly handled, allowing to inject options into munin-cgi-graph and overwriting any file accessible by the user running the cgi-process.

For the stable distribution (jessie), this problem has been fixed in version 2.0.25-1+deb8u1.

We recommend that you upgrade your munin packages.