5
CVSSv2

CVE-2013-6048

Published: 13/12/2013 Updated: 06/03/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin prior to 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data.

Vulnerable Product Search on Vulmon Subscribe to Product

munin-monitoring munin 2.0.14

munin-monitoring munin 2.0.13

munin-monitoring munin 2.0.7

munin-monitoring munin 2.0.6

munin-monitoring munin 2.0.16

munin-monitoring munin 2.0.15

munin-monitoring munin 2.0.9

munin-monitoring munin 2.0.8

munin-monitoring munin 2.0.0

munin-monitoring munin

munin-monitoring munin 2.0.11.1

munin-monitoring munin 2.0.10

munin-monitoring munin 2.0.3

munin-monitoring munin 2.0.2

munin-monitoring munin 2.0.1

munin-monitoring munin 2.0.12

munin-monitoring munin 2.0.11

munin-monitoring munin 2.0.5

munin-monitoring munin 2.0.4

Vendor Advisories

Several security issues were fixed in Munin ...
Christoph Biedl discovered two denial of service vulnerabilities in munin, a network-wide graphing framework The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-6048 The Munin::Master::Node module of munin does not properly validate certain data a node sends A malicious node might exploit this to ...
The get_group_tree function in lib/Munin/Master/HTMLConfigpm in Munin before 2018 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data Munin::Master::Node in Munin before 2018 allows remote attackers to cause a denial of service (abort data collection for ...
The get_group_tree function in lib/Munin/Master/HTMLConfigpm in Munin before 2018 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data Munin::Master::Node in Munin before 2018 allows remote attackers to cause a denial of service (abort data collection fo ...