~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
PublicDateAtUSN: 2017-02-22
Candidate: CVE-2017-6188
PublicDate: 2017-02-22
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6188
 http://www.ubuntu.com/usn/usn-3215-1
Description:
 Munin before 2.999.6 has a local file write vulnerability when CGI graphs
 are enabled. Setting multiple upper_limit GET parameters allows overwriting
 any file accessible to the www-data user.
Ubuntu-Description:
Notes:
Bugs:
 https://github.com/munin-monitoring/munin/issues/721
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=855705
Priority: medium
Discovered-by:
Assigned-to: mdeslaur

Patches_munin:
 upstream: https://github.com/munin-monitoring/munin/commit/42ce18f24d3eae8be33526a198bf21e4f2330230
 upstream: https://github.com/munin-monitoring/munin/commit/549bd25d6a45e153159ef8535fc070a71093a3c9
upstream_munin: released (2.0.31)
precise_munin: not-affected (code not present)
trusty_munin: released (2.0.19-3ubuntu0.2)
vivid/stable-phone-overlay_munin: DNE
vivid/ubuntu-core_munin: DNE
xenial_munin: released (2.0.25-2ubuntu0.16.04.2)
yakkety_munin: released (2.0.25-2ubuntu0.16.10.2)
devel_munin: not-affected (2.0.31-1)