PT-2012-3810 · Munin · Munin

Jan Lieskovsky

·

Published

2012-08-26

·

Updated

2018-10-23

·

CVE-2012-2104

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Munin versions 2.x
Description The issue allows user-assisted remote attackers to inject terminal emulator escape sequences and execute arbitrary commands or delete arbitrary files via a crafted HTTP request to the "cgi-bin/munin-cgi-graph" endpoint. This is due to the software writing data to a log file without sanitizing non-printable characters.
Recommendations For Munin versions 2.x, update to a version that sanitizes non-printable characters in log files to prevent terminal emulator escape sequence injection. As a temporary workaround, consider restricting access to the "cgi-bin/munin-cgi-graph" endpoint until a patch is available.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2104

Affected Products

Munin