ALAS-2014-275


Amazon Linux AMI Security Advisory: ALAS-2014-275
Advisory Release Date: 2014-09-16 22:18 Pacific
Severity: Medium

Issue Overview:

The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data.

Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name.


Affected Packages:

munin


Issue Correction:
Run yum update munin to update your system.

New Packages:
noarch:
    munin-cgi-2.0.19-1.32.amzn1.noarch
    munin-common-2.0.19-1.32.amzn1.noarch
    munin-node-2.0.19-1.32.amzn1.noarch
    munin-nginx-2.0.19-1.32.amzn1.noarch
    munin-netip-plugins-2.0.19-1.32.amzn1.noarch
    munin-2.0.19-1.32.amzn1.noarch
    munin-java-plugins-2.0.19-1.32.amzn1.noarch
    munin-async-2.0.19-1.32.amzn1.noarch
    munin-ruby-plugins-2.0.19-1.32.amzn1.noarch

src:
    munin-2.0.19-1.32.amzn1.src