Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
CVE-2017-6188: Upstream PR 797: Fix wrong parameter expansion in CGI. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-3776c9d747 2017-03-10 09:58:41.327465 -------------------------------------------------------------------------------- Name : munin Product : Fedora 25 Version : 2.0.30 Release : 5.fc25 URL : http://munin-monitoring.org/ Summary : Network-wide graphing framework (grapher/gatherer) Description : Munin is a highly flexible and powerful solution used to create graphs of virtually everything imaginable throughout your network, while still maintaining a rattling ease of installation and configuration. This package contains the grapher/gatherer. You will only need one instance of it in your network. It will periodically poll all the nodes in your network it's aware of for data, which it in turn will use to create graphs and HTML pages, suitable for viewing with your graphical web browser of choice. Munin is written in Perl, and relies heavily on Tobi Oetiker's excellent RRDtool. Creaete a munin web user after installing: htpasswd -bc /etc/munin/munin-htpasswd MUNIN_WEB_USER PASSWORD -------------------------------------------------------------------------------- Update Information: CVE-2017-6188: Upstream PR 797: Fix wrong parameter expansion in CGI -------------------------------------------------------------------------------- References: [ 1 ] Bug #1425855 - CVE-2017-6188 munin: Local file write vulnerability with CGI graphs enabled https://bugzilla.redhat.com/show_bug.cgi?id=1425855 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade munin' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
CVE-2017-6188: Upstream PR 797: Fix wrong parameter expansion in CGI. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-25df1dbd02 2017-03-10 09:58:39.667493 -------------------------------------------------------------------------------- Name : munin Product : Fedora 24 Version : 2.0.30 Release : 5.fc24 URL : http://munin-monitoring.org/ Summary : Network-wide graphing framework (grapher/gatherer) Description : Munin is a highly flexible and powerful solution used to create graphs of virtually everything imaginable throughout your network, while still maintaining a rattling ease of installation and configuration. This package contains the grapher/gatherer. You will only need one instance of it in your network. It will periodically poll all the nodes in your network it's aware of for data, which it in turn will use to create graphs and HTML pages, suitable for viewing with your graphical web browser of choice. Munin is written in Perl, and relies heavily on Tobi Oetiker's excellent RRDtool. Creaete a munin web user after installing: htpasswd -bc /etc/munin/munin-htpasswd MUNIN_WEB_USER PASSWORD -------------------------------------------------------------------------------- Update Information: CVE-2017-6188: Upstream PR 797: Fix wrong parameter expansion in CGI -------------------------------------------------------------------------------- References: [ 1 ] Bug #1425855 - CVE-2017-6188 munin: Local file write vulnerability with CGI graphs enabled https://bugzilla.redhat.com/show_bug.cgi?id=1425855 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade munin' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for munin ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:0621-1 Rating: important References: #1026539 Cross-References: CVE-2017-6188 Affected Products: openSUSE Leap 42.2 openSUSE Leap 42.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for munin fixes the following issues: - An attacker has been able to write arbitrary local files with the permissions of the web server, by using parameter injection (boo#1026539, CVE-2017-6188) - The MySQL plugin has been fixed to work correctly against MySQL 5.5 on Leap 42.1 Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.2: zypper in -t patch openSUSE-2017-310=1 - openSUSE Leap 42.1: zypper in -t patch openSUSE-2017-310=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.2 (noarch): munin-2.0.25-9.1 munin-node-2.0.25-9.1 - openSUSE Leap 42.1 (noarch): munin-2.0.25-7.1 munin-node-2.0.25-7.1 References: https://www.suse.com/security/cve/CVE-2017-6188.html https://bugzilla.suse.com/1026539 . A significant patch for munin tackles severe vulnerabilities in openSUSE Leap. Make sure your system is updated!. OpenSUSE Security, Munin Update, Parameter Injection Threat. . Severity: Important. LinuxSecurity.com Team
The update for munin issued as DSA-3794-2 caused a regression leading to Perl warnings being appended to the munin-cgi-graph log file. Updated packages are now available to correct this issue. For reference, the original advisory text follows. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3794-3
USN-3215-1 introduced a regression in Munin.. =========================================================================Ubuntu Security Notice USN-3215-2 March 03, 2017 munin regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: USN-3215-1 introduced a regression in Munin. Software Description: - munin: Network-wide graphing framework Details: USN-3215-1 fixed a vulnerability in Munin. The upstream patch caused a regression leading to errors being appended to the log file. This update fixes the problem. Original advisory details: It was discovered that Munin incorrectly handled CGI graphs. A remote attacker could use this issue to overwrite arbitrary files as the www-data user. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: munin 2.0.19-3ubuntu0.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3215-2 https://ubuntu.com/security/notices/USN-3215-1 https://bugs.launchpad.net/ubuntu/+source/munin/+bug/1669764 Package Information: https://launchpad.net/ubuntu/+source/munin/2.0.19-3ubuntu0.3 . Security Advisory USN-4621-1 outlines a bug in Nagios for Ubuntu 18.04, addressing complications arising from a previous patch.. Ubuntu Security Notice, Munin Update, Regression Fix. . Severity: Critical. LinuxSecurity.com Team
Munin could be made to overwrite files.. =========================================================================Ubuntu Security Notice USN-3215-1 March 02, 2017 munin vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Munin could be made to overwrite files. Software Description: - munin: Network-wide graphing framework Details: It was discovered that Munin incorrectly handled CGI graphs. A remote attacker could use this issue to overwrite arbitrary files as the www-data user. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: munin 2.0.19-3ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3215-1 CVE-2017-6188 Package Information: https://launchpad.net/ubuntu/+source/munin/2.0.19-3ubuntu0.2 . A vulnerability found in Munin may lead to unauthorized file overwrites. To safeguard against this potential remote exploit, it is advisable to upgrade your Ubuntu system.. munin security, ubuntu update, file overwrite, remote attack, cgi vulnerability. . LinuxSecurity.com Team
The update for munin issues as DSA-3794-1 caused a regression in the zooming functionality in munin-cgi-graph. Updated packages are now available to correct this issue. For reference, the original advisory text follows. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3794-2
Stevie Trujillo discovered a local file write vulnerability in munin, a network-wide graphing framework, when CGI graphs are enabled. GET parameters are not properly handled, allowing to inject options into munin-cgi-graph and overwriting any file accessible accessible by the . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3794-1
Get the latest Linux and open source security news straight to your inbox.