ALAS-2017-818


Amazon Linux 1 Security Advisory: ALAS-2017-818
Advisory Release Date: 2017-04-20 06:03 Pacific
Advisory Updated Date: 2017-04-20 22:06 Pacific
Severity: Medium

Issue Overview:

Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user. (CVE-2017-6188)


Affected Packages:

munin


Issue Correction:
Run yum update munin to update your system.

New Packages:
noarch:
    munin-cgi-2.0.30-5.38.amzn1.noarch
    munin-ruby-plugins-2.0.30-5.38.amzn1.noarch
    munin-node-2.0.30-5.38.amzn1.noarch
    munin-netip-plugins-2.0.30-5.38.amzn1.noarch
    munin-2.0.30-5.38.amzn1.noarch
    munin-common-2.0.30-5.38.amzn1.noarch
    munin-java-plugins-2.0.30-5.38.amzn1.noarch
    munin-nginx-2.0.30-5.38.amzn1.noarch
    munin-async-2.0.30-5.38.amzn1.noarch

src:
    munin-2.0.30-5.38.amzn1.src