CVE-2012-2147
Published: 26 August 2012
munin-cgi-graph in Munin 2.0 rc4 allows remote attackers to cause a denial of service (disk or memory consumption) via many image requests with large values in the (1) size_x or (2) size_y parameters.
Notes
Author | Note |
---|---|
mdeslaur | reproducer in debian bug 1.x doesn't support size_x and size_y |
Priority
Status
Package | Release | Status |
---|---|---|
munin Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Not vulnerable
|
|
natty |
Not vulnerable
|
|
oneiric |
Not vulnerable
|
|
precise |
Not vulnerable
|
|
upstream |
Released
(2.0~rc6-1)
|
|
Patches: upstream: http://anonscm.debian.org/gitweb/?p=collab-maint/munin.git;a=commit;h=0ec9b3ae01fe9faf198120281e68b80da6200c55 upstream: http://anonscm.debian.org/gitweb/?p=collab-maint/munin.git;a=commit;h=26fbc97b17b20d01edcf3d3d0c3dd6d9a2a062f8 |