5
CVSSv2

CVE-2012-2147

Published: 26/08/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

munin-cgi-graph in Munin 2.0 rc4 allows remote malicious users to cause a denial of service (disk or memory consumption) via many image requests with large values in the (1) size_x or (2) size_y parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

munin-monitoring munin 2.0_rc4

Vendor Advisories

Debian Bug report logs - #670811 munin-cgi-graph: add image size limits to avoid distant DoS via OOM Package: munin; Maintainer for munin is Munin Debian Maintainers <team+munin@trackerdebianorg>; Source for munin is src:munin (PTS, buildd, popcon) Reported by: Helmut Grohne <helmut@subdivide> Date: Fri, 13 Apr 20 ...
Debian Bug report logs - #668667 munin-cgi-graph: remote users can fill the /tmp filesystem Package: munin; Maintainer for munin is Munin Debian Maintainers <team+munin@trackerdebianorg>; Source for munin is src:munin (PTS, buildd, popcon) Reported by: Helmut Grohne <helmut@subdivide> Date: Fri, 13 Apr 2012 21:54: ...