Lucene search

K
cve[email protected]CVE-2012-3512
HistoryNov 21, 2012 - 11:55 p.m.

CVE-2012-3512

2012-11-2123:55:01
CWE-264
web.nvd.nist.gov
31
munin
vulnerability
local users
arbitrary code
cve-2012-3512
nvd

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to execute arbitrary code by replacing a state file, as demonstrated using the smart_ plugin.

Affected configurations

NVD
Node
munin-monitoringmuninRange2.0.5
OR
munin-monitoringmuninMatch2.0-beta1
OR
munin-monitoringmuninMatch2.0-beta2
OR
munin-monitoringmuninMatch2.0-beta3
OR
munin-monitoringmuninMatch2.0-beta4
OR
munin-monitoringmuninMatch2.0-beta5
OR
munin-monitoringmuninMatch2.0-beta6
OR
munin-monitoringmuninMatch2.0-beta7
OR
munin-monitoringmuninMatch2.0-rc1
OR
munin-monitoringmuninMatch2.0-rc2
OR
munin-monitoringmuninMatch2.0-rc3
OR
munin-monitoringmuninMatch2.0-rc4
OR
munin-monitoringmuninMatch2.0-rc5
OR
munin-monitoringmuninMatch2.0-rc6
OR
munin-monitoringmuninMatch2.0-rc7
OR
munin-monitoringmuninMatch2.0.0
OR
munin-monitoringmuninMatch2.0.1
OR
munin-monitoringmuninMatch2.0.2
OR
munin-monitoringmuninMatch2.0.3
OR
munin-monitoringmuninMatch2.0.4

7.2 High

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%