Vulnerability Bulletins

DSA-3794 munin - security update

   
Affected software Debian
 
Stevie Trujillo discovered a local file write vulnerability in munin, anetwork-wide graphing framework, when CGI graphs are enabled. GETparameters are not properly handled, allowing to inject options intomunin-cgi-graph and overwriting any file accessible by the userrunning the cgi-process.

More info:

https://www.debian.org/security/2017/dsa-3794