9.3
CVSSv2

CVE-2012-3513

Published: 21/11/2012 Updated: 23/11/2012
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

munin-cgi-graph in Munin prior to 2.0.6, when running as a CGI module under Apache, allows remote malicious users to load new configurations and create files in arbitrary directories via the logdir command.

Vulnerable Product Search on Vulmon Subscribe to Product

munin-monitoring munin 2.0-beta7

munin-monitoring munin 2.0-beta6

munin-monitoring munin 2.0-beta5

munin-monitoring munin 2.0-beta4

munin-monitoring munin 2.0.4

munin-monitoring munin 2.0-rc5

munin-monitoring munin 2.0-rc3

munin-monitoring munin 2.0-beta2

munin-monitoring munin 2.0-rc2

munin-monitoring munin 2.0.2

munin-monitoring munin 2.0.1

munin-monitoring munin 2.0.0

munin-monitoring munin 2.0-rc7

munin-monitoring munin 2.0-rc6

munin-monitoring munin

munin-monitoring munin 2.0.3

munin-monitoring munin 2.0-rc4

munin-monitoring munin 2.0-rc1

munin-monitoring munin 2.0-beta3

munin-monitoring munin 2.0-beta1

Vendor Advisories

Several security issues were fixed in Munin ...
Debian Bug report logs - #684075 munin: CVE-2012-3512: insecure state file handling, munin->root Package: munin-plugins-core; Maintainer for munin-plugins-core is Munin Debian Maintainers <team+munin@trackerdebianorg>; Source for munin-plugins-core is src:munin (PTS, buildd, popcon) Reported by: Stevie Trujillo <stev ...
Debian Bug report logs - #684076 munin-cgi-graph: User can load new config, pointing log to arbitrary file Package: munin; Maintainer for munin is Munin Debian Maintainers <team+munin@trackerdebianorg>; Source for munin is src:munin (PTS, buildd, popcon) Reported by: Stevie Trujillo <stevietrujillo@gmailcom> Date ...