munin-cgi-graph for Munin 2.0 rc4 does not delete temporary files, which allows remote attackers to cause a denial of service (disk consumption) via many requests to an image with unique parameters.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Munin | Munin-monitoring | 2.0_rc4 (including) | 2.0_rc4 (including) |
Munin | Ubuntu | hardy | * |
Munin | Ubuntu | upstream | * |