CVE-2012-3512

Publication date 21 August 2012

Last updated 24 July 2024


Ubuntu priority

Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to execute arbitrary code by replacing a state file, as demonstrated using the smart_ plugin.

Read the notes from the security team

Status

Package Ubuntu Release Status
munin 12.10 quantal
Fixed 2.0.2-1ubuntu2.2
12.04 LTS precise
Fixed 1.4.6-3ubuntu3.3
11.10 oneiric
Fixed 1.4.5-3ubuntu4.11.10.2
11.04 natty Ignored end of life
10.04 LTS lucid
Fixed 1.4.4-1ubuntu1.2
8.04 LTS hardy Ignored end of life

Notes


sbeattie

munin user/group to root escalation

References

Related Ubuntu Security Notices (USN)

    • USN-1622-1
    • Munin vulnerabilities
    • 5 November 2012

Other references