munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.ubuntu.com/usn/USN-1622-1 | vendor advisory |
http://www.openwall.com/lists/oss-security/2012/08/21/1 | mailing list |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=684076 | |
http://www.munin-monitoring.org/ticket/1238 | exploit vendor advisory |