CVE-2012-3512

Public on 2012-10-08
Modified on 2014-09-14
Description
Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to execute arbitrary code by replacing a state file, as demonstrated using the smart_ plugin.
Severity
Important severity
Important
CVSS v3 Base Score
7.2
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 munin 2012-10-08 ALAS-2012-130 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv2 7.2 AV:L/AC:L/Au:N/C:C/I:C/A:C
NVD CVSSv2 7.2 AV:L/AC:L/Au:N/C:C/I:C/A:C