[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250038

 
 

909

 
 

195843

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-2815-1 munin -- denial of service

ID: oval:org.secpod.oval:def:601167Date: (C)2014-01-08   (M)2022-10-10
Class: PATCHFamily: unix




Christoph Biedl discovered two denial of service vulnerabilities in munin, a network-wide graphing framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-6048 The Munin::Master::Node module of munin does not properly validate certain data a node sends. A malicious node might exploit this to drive the munin-html process into an infinite loop with memory exhaustion on the munin master. CVE-2013-6359 A malicious node, with a plugin enabled using "multigraph" as a multigraph service name, can abort data collection for the entire node the plugin runs on.

Platform:
Debian 7.0
Product:
munin
Reference:
DSA-2815-1
CVE-2013-6048
CVE-2013-6359
CVE    2
CVE-2013-6359
CVE-2013-6048
CPE    21
cpe:/a:munin-monitoring:munin:2.0.4
cpe:/a:munin-monitoring:munin:2.0.3
cpe:/a:munin-monitoring:munin:2.0.6
cpe:/a:munin-monitoring:munin:2.0.5
...

© SecPod Technologies