Munin: Arbitrary file write A vulnerability in Munin allows local attackers to overwrite any file accessible to the www-data user. munin 2017-10-08 2017-10-08 610602 local 2.0.33 2.0.33

Munin is an open source server monitoring tool.

When Munin is compiled with CGI graphics enabled then the files accessible to the www-data user can be overwritten.

A local attacker, by setting multiple upper_limit GET parameters, could overwrite files accessible to the www-user.

There is no known workaround at this time.

All Munin users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=net-analyzer/munin-2.0.33"
CVE-2017-6188 chrisadr chrisadr