CVE-2011-3741
Publication date 23 September 2011
Last updated 24 July 2024
Ubuntu priority
Description
Ganglia 3.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by host_view.php and certain other files.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ganglia | 18.04 LTS bionic | Ignored |
| 16.04 LTS xenial | Ignored | |
| 14.04 LTS trusty | Ignored | |
Notes
debian
NOT-FOR-US: Web app path disclosure, not an issue (path is known anyway)
msalvatore
I'm retiring this because the version of ganglia in trusty is 3.6.0-1ubuntu2, vs the affected version of 3.1.7. Additionally, Debian has this labeled as "NOT-FOR-US".