CVE-2013-6048Improper Input Validation in Munin

Severity
5.0MEDIUMNVD
EPSS
0.5%
top 32.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13
Latest updateMay 17

Description

The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

debiandebian/munin< munin 2.0.18-1 (bookworm)
Debianmunin-monitoring/munin< 2.0.18-1+3
NVDmunin-monitoring/munin2.0.17+18

Patches

🔴Vulnerability Details

2
GHSA
GHSA-mv2m-5r86-9xcj: The get_group_tree function in lib/Munin/Master/HTMLConfig2022-05-17
OSV
CVE-2013-6048: The get_group_tree function in lib/Munin/Master/HTMLConfig2013-12-13

📋Vendor Advisories

2
Ubuntu
Munin vulnerabilities2014-01-27
Debian
CVE-2013-6048: munin - The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2....2013

💬Community

3
Bugzilla
CVE-2013-6048 CVE-2013-6359 munin: two denial of service flaws fixed in 2.0.182013-12-04
Bugzilla
CVE-2013-6048 CVE-2013-6359 munin: two denial of service flaws fixed in 2.0.18 [epel-all]2013-12-04
Bugzilla
CVE-2013-6048 CVE-2013-6359 munin: two denial of service flaws fixed in 2.0.18 [fedora-all]2013-12-04