Munin CVE-2012-3512 Insecure File Permissions Vulnerability
BID:55698
Info
Munin CVE-2012-3512 Insecure File Permissions Vulnerability
| Bugtraq ID: | 55698 |
| Class: | Design Error |
| CVE: |
CVE-2012-3512 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 26 2012 12:00AM |
| Updated: | Apr 13 2015 09:51PM |
| Credit: | kenyon |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Munin Munin 1.4.5-3 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Munin CVE-2012-3512 Insecure File Permissions Vulnerability
Munin is prone to an insecure file-permission.
A local attacker can exploit this issue to execute arbitrary code with root privileges. This may aid in further attacks.
Munin is prone to an insecure file-permission.
A local attacker can exploit this issue to execute arbitrary code with root privileges. This may aid in further attacks.
Exploit / POC
Munin CVE-2012-3512 Insecure File Permissions Vulnerability
Attackers require local interactive access to exploit this issue.
Attackers require local interactive access to exploit this issue.
Solution / Fix
Munin CVE-2012-3512 Insecure File Permissions Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
Solution:
Vendor updates are available. Please see the references for more information.
Mandriva Business Server 1 X86 64
-
Mandriva munin-2.0-0.rc5.3.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva munin-master-2.0-0.rc5.3.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva munin-node-2.0-0.rc5.3.1.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/
References
Munin CVE-2012-3512 Insecure File Permissions Vulnerability
References:
References: