MGASA-2013-0378
Dashboard / Vulnerabilities / MGASA-2013-0378
Summary: Updated munin packages fixes two security vulnerabilities
Details: Updated munin packages fix security vulnerabilities: The Munin::Master::Node module of munin does not properly validate certain data a node sends. A malicious node might exploit this to drive the munin-html process into an infinite loop with memory exhaustion on the munin master (CVE-2013-6048). A malicious node, with a plugin enabled using "multigraph" as a multigraph service name, can abort data collection for the entire node the plugin runs on (CVE-2013-6359).
References: https://advisories.mageia.org/MGASA-2013-0378.html, http://www.debian.org/security/2013/dsa-2815, https://bugs.mageia.org/show_bug.cgi?id=11944
Affected packages
Package
Name: munin
Purl: pkg:rpm/mageia/munin?arch=source&distro=mageia-3
Affected ranges
Type: ECOSYSTEM
Events:
