CVE-2013-6359Improper Input Validation in Munin

Severity
4.3MEDIUMNVD
EPSS
0.7%
top 27.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13
Latest updateMay 17

Description

Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/munin< munin 2.0.18-1 (bookworm)
Debianmunin-monitoring/munin< 2.0.18-1+3
NVDmunin-monitoring/munin2.0.17+18

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f92f-4f5p-xhfm: Munin::Master::Node in Munin before 22022-05-17
OSV
CVE-2013-6359: Munin::Master::Node in Munin before 22013-12-13

📋Vendor Advisories

2
Ubuntu
Munin vulnerabilities2014-01-27
Debian
CVE-2013-6359: munin - Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a de...2013

💬Community

3
Bugzilla
CVE-2013-6048 CVE-2013-6359 munin: two denial of service flaws fixed in 2.0.182013-12-04
Bugzilla
CVE-2013-6048 CVE-2013-6359 munin: two denial of service flaws fixed in 2.0.18 [epel-all]2013-12-04
Bugzilla
CVE-2013-6048 CVE-2013-6359 munin: two denial of service flaws fixed in 2.0.18 [fedora-all]2013-12-04