Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-2147
HistoryAug 26, 2012 - 12:00 a.m.

CVE-2012-2147

2012-08-2600:00:00
ubuntu.com
ubuntu.com
7

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.038

Percentile

91.9%

munin-cgi-graph in Munin 2.0 rc4 allows remote attackers to cause a denial
of service (disk or memory consumption) via many image requests with large
values in the (1) size_x or (2) size_y parameters.

Bugs

Notes

Author Note
mdeslaur reproducer in debian bug 1.x doesn’t support size_x and size_y

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.038

Percentile

91.9%

Related for UB:CVE-2012-2147