Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

Ubuntu: 2090-1 Moderately Severe: Munin DoS Threats and Fixes

ubuntu
Calendar Grey January 27, 2014
Scroller Ubuntu
Ensure your Ubuntu systems are safeguarded from Munin vulnerabilities by identifying affected versions, updating repositories, and upgrading the package to the latest stable release
Several security issues were fixed in Munin.

Summary

Several security issues were fixed in Munin.

Software Description:

- munin: Network-wide graphing framework

Details:

Christoph Biedl discovered that Munin incorrectly handled certain

multigraph data. A remote attacker could use this issue to cause Munin to

consume resources, resulting in a denial of service. (CVE-2013-6048)

Christoph Biedl discovered that Munin incorrectly handled certain

multigraph service names. A remote attacker could use this issue to cause

Munin to stop data collection, resulting in a denial of service.

(CVE-2013-6359)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  munin                           2.0.17-2ubuntu1.1

Ubuntu 12.10:
  munin                           2.0.2-1ubuntu2.3

Ubuntu 12.04 LTS:
  munin                           1.4.6-3ubuntu3.4

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2090-1

CVE-2013-6048, CVE-2013-6359

January 27, 2014

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.