=========================================================================Ubuntu Security Notice USN-3215-2 March 03, 2017 munin regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: USN-3215-1 introduced a regression in Munin. Software Description: - munin: Network-wide graphing framework Details: USN-3215-1 fixed a vulnerability in Munin. The upstream patch caused a regression leading to errors being appended to the log file. This update fixes the problem. Original advisory details: It was discovered that Munin incorrectly handled CGI graphs. A remote attacker could use this issue to overwrite arbitrary files as the www-data user. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: munin 2.0.19-3ubuntu0.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3215-2 https://ubuntu.com/security/notices/USN-3215-1 https://bugs.launchpad.net/ubuntu/+source/munin/+bug/1669764 Package Information: https://launchpad.net/ubuntu/+source/munin/2.0.19-3ubuntu0.3
The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: munin 2.0.19-3ubuntu0.3 In general, a standard system update will make all the necessary changes.
https://ubuntu.com/security/notices/USN-3215-2
https://ubuntu.com/security/notices/USN-3215-1
https://bugs.launchpad.net/ubuntu/+source/munin/+bug/1669764
https://launchpad.net/ubuntu/+source/munin/2.0.19-3ubuntu0.3
Get the latest Linux and open source security news straight to your inbox.