CVE Vulnerabilities

CVE-2012-3513

Published: Nov 21, 2012 | Modified: Nov 23, 2012
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.

Affected Software

Name Vendor Start Version End Version
Munin Munin-monitoring * 2.0.5 (including)
Munin Munin-monitoring 2.0-beta1 (including) 2.0-beta1 (including)
Munin Munin-monitoring 2.0-beta2 (including) 2.0-beta2 (including)
Munin Munin-monitoring 2.0-beta3 (including) 2.0-beta3 (including)
Munin Munin-monitoring 2.0-beta4 (including) 2.0-beta4 (including)
Munin Munin-monitoring 2.0-beta5 (including) 2.0-beta5 (including)
Munin Munin-monitoring 2.0-beta6 (including) 2.0-beta6 (including)
Munin Munin-monitoring 2.0-beta7 (including) 2.0-beta7 (including)
Munin Munin-monitoring 2.0-rc1 (including) 2.0-rc1 (including)
Munin Munin-monitoring 2.0-rc2 (including) 2.0-rc2 (including)
Munin Munin-monitoring 2.0-rc3 (including) 2.0-rc3 (including)
Munin Munin-monitoring 2.0-rc4 (including) 2.0-rc4 (including)
Munin Munin-monitoring 2.0-rc5 (including) 2.0-rc5 (including)
Munin Munin-monitoring 2.0-rc6 (including) 2.0-rc6 (including)
Munin Munin-monitoring 2.0-rc7 (including) 2.0-rc7 (including)
Munin Munin-monitoring 2.0.0 (including) 2.0.0 (including)
Munin Munin-monitoring 2.0.1 (including) 2.0.1 (including)
Munin Munin-monitoring 2.0.2 (including) 2.0.2 (including)
Munin Munin-monitoring 2.0.3 (including) 2.0.3 (including)
Munin Munin-monitoring 2.0.4 (including) 2.0.4 (including)
Munin Ubuntu devel *
Munin Ubuntu hardy *
Munin Ubuntu quantal *
Munin Ubuntu upstream *

References