Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 3794-1] munin security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 3794-1] munin security update


Chronologisch Thread 
  • From: Salvatore Bonaccorso <carnil AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 3794-1] munin security update
  • Date: Sat, 25 Feb 2017 20:37:50 +0000
  • List-archive: https://lists.debian.org/msgid-search/E1chj6E-0005yE-Dw AT master.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-return-path: <carnil AT master.debian.org>
  • Priority: urgent
  • Resent-date: Sat, 25 Feb 2017 20:38:06 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <0PfJlnBeCUP.A.jdH.usesYB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3794-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
February 25, 2017 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : munin
CVE ID : CVE-2017-6188
Debian Bug : 855705

Stevie Trujillo discovered a local file write vulnerability in munin, a
network-wide graphing framework, when CGI graphs are enabled. GET
parameters are not properly handled, allowing to inject options into
munin-cgi-graph and overwriting any file accessible accessible by the
user running the cgi-process.

For the stable distribution (jessie), this problem has been fixed in
version 2.0.25-1+deb8u1.

We recommend that you upgrade your munin packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAlix6vhfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0SQTg//WXRyiDkW5irOue8t7kYmI2UE6AL+1eakYmxl23HkiAdB6puBcsRZS559
P8d0tN6aFxiM+p2Cl651V+RCS+K4vi7HGvu6r7qSDXGW0S1BA7NrRUM5eAlebdAP
yxqnz/iD8ghuBn7HEUtBzKomkapBvk7XniRDV57Add5iMVVM5iXjLBHgXp+iL9r6
UABFY7TBVm7EW0u3z0CL2whuMzqE7d4ggZD+AGL7G0BNnAR8/KNyW3G00aEwEeb5
k3yBmEDjTut17gdeX9WvSAjA9uigSpLri1geUubRxV8CoG8ZE6Ka55uIh8enDAOO
G7CWlJogS+h95fJFNFAjQTvmqEy/RbROXBuA94aE9IzZttOE0774wCHDhteGaYgM
uO22AXFlgYMLoeohSE7385EmjDyIYGsL/wYXlOkbZzeppUmvidBc6zR3JK03BS7a
SgC853CyfUU6rCdXOgLPa5Z1pDDnArcfk9hU2Z472wiUpiRvXM8OuBHrj+YH/UbC
Ygq5H4ymb76a5EqEm83fnHXRotnYvvWluGZ8A4ZpnrvPTgJ5h0c3Ugt2uGcyICo8
Y+OBypehyaeJjIyUSkq8A2Zb74VvISbHO4i+goRW9wDje23T8Gj3vjOyXuoot+XF
CscqihAQhJZwWyUEZqmlh3rPucXk1ETPy47RRbbW3nLSSXRrvTw=
=8YsW
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 3794-1] munin security update, Salvatore Bonaccorso, 25.02.2017

Archiv bereitgestellt durch MHonArc 2.6.19.

Seitenanfang