CVE-2012-2103Link Following in Munin

CWE-59Link Following6 documents6 sources
Severity
1.2LOWNVD
EPSS
0.0%
top 88.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 26
Latest updateMay 17

Description

The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

CVSS vector

AV:L/AC:H/C:N/I:P/A:NExploitability: 1.9 | Impact: 2.9

Affected Packages3 packages

debiandebian/munin< munin 2.0~rc6-1 (bookworm)
Debianmunin-monitoring/munin< 2.0~rc6-1+3

🔴Vulnerability Details

2
GHSA
GHSA-wp9g-5pp9-hxcm: The qmailscan plugin for Munin 12022-05-17
OSV
CVE-2012-2103: The qmailscan plugin for Munin 12012-08-26

📋Vendor Advisories

2
Ubuntu
Munin vulnerabilities2012-11-05
Debian
CVE-2012-2103: munin - The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary f...2012

💬Community

1
Bugzilla
CVE-2012-2103 munin: Insecure temp file use in qmailscan plug-in2012-04-16