Lucene search

K
amazonAmazonALAS-2014-275
HistoryJan 14, 2014 - 3:57 p.m.

Medium: munin

2014-01-1415:57:00
alas.aws.amazon.com
9

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.007 Low

EPSS

Percentile

80.3%

Issue Overview:

The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data.

Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses “multigraph” as a multigraph service name.

Affected Packages:

munin

Issue Correction:
Run yum update munin to update your system.

New Packages:

noarch:  
    munin-cgi-2.0.19-1.32.amzn1.noarch  
    munin-common-2.0.19-1.32.amzn1.noarch  
    munin-node-2.0.19-1.32.amzn1.noarch  
    munin-nginx-2.0.19-1.32.amzn1.noarch  
    munin-netip-plugins-2.0.19-1.32.amzn1.noarch  
    munin-2.0.19-1.32.amzn1.noarch  
    munin-java-plugins-2.0.19-1.32.amzn1.noarch  
    munin-async-2.0.19-1.32.amzn1.noarch  
    munin-ruby-plugins-2.0.19-1.32.amzn1.noarch  
  
src:  
    munin-2.0.19-1.32.amzn1.src  

Additional References

Red Hat: CVE-2013-6048, CVE-2013-6359

Mitre: CVE-2013-6048, CVE-2013-6359

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

0.007 Low

EPSS

Percentile

80.3%