CVE-2012-4678
CVE-2012-4678
munin-cgi-graph for Munin 2.0 rc4 does not delete temporary files, which allows remote attackers to cause a denial of service (disk consumption) via many requests to an image with unique parameters.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=668667http://munin-monitoring.org/changeset/4825https://bugzilla.redhat.com/show_bug.cgi?id=812889http://www.openwall.com/lists/oss-security/2012/04/16/5http://www.openwall.com/lists/oss-security/2012/04/16/6http://www.openwall.com/lists/oss-security/2012/04/18/2http://www.openwall.com/lists/oss-security/2012/04/19/3http://www.openwall.com/lists/oss-security/2012/04/19/4http://www.openwall.com/lists/oss-security/2012/04/19/5http://www.openwall.com/lists/oss-security/2012/04/27/7http://www.openwall.com/lists/oss-security/2012/04/29/2http://www.securityfocus.com/bid/53034