A vulnerability in Munin allows local attackers to overwrite any file accessible to the www-data user.
Package | net-analyzer/munin on all architectures |
---|---|
Affected versions | < 2.0.33 |
Unaffected versions | >= 2.0.33 |
Munin is an open source server monitoring tool.
When Munin is compiled with CGI graphics enabled then the files accessible to the www-data user can be overwritten.
A local attacker, by setting multiple upper_limit GET parameters, could overwrite files accessible to the www-user.
There is no known workaround at this time.
All Munin users should upgrade to the latest version:
# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/munin-2.0.33"
Release date
October 08, 2017
Latest revision
October 08, 2017: 1
Severity
normal
Exploitable
local
Bugzilla entries