Amazon Linux 1 Security Advisory: ALAS-2014-348
Advisory Release Date: 2014-06-03 15:03 Pacific
Advisory Updated Date: 2014-09-18 00:39 Pacific
The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data.
Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name.
Affected Packages:
munin
Issue Correction:
Run yum update munin to update your system.
noarch:
munin-async-2.0.20-1.36.amzn1.noarch
munin-nginx-2.0.20-1.36.amzn1.noarch
munin-cgi-2.0.20-1.36.amzn1.noarch
munin-ruby-plugins-2.0.20-1.36.amzn1.noarch
munin-2.0.20-1.36.amzn1.noarch
munin-netip-plugins-2.0.20-1.36.amzn1.noarch
munin-common-2.0.20-1.36.amzn1.noarch
munin-node-2.0.20-1.36.amzn1.noarch
munin-java-plugins-2.0.20-1.36.amzn1.noarch
src:
munin-2.0.20-1.36.amzn1.src