CVE-2012-3512
Published Nov 21, 2012
Last updated 12 years ago
Overview
- Description
- Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to execute arbitrary code by replacing a state file, as demonstrated using the smart_ plugin.
- Source
- secalert@redhat.com
- NVD status
- Modified
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-264
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:munin-monitoring:munin:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1286861D-C595-4ED2-8A04-F68108B30245", "versionEndIncluding": "2.0.5" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-beta1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "62D36651-D8E6-4DF9-8DF2-01523F6D0C19" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-beta2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE3B639A-A0E6-4B07-B39C-F751D9CFD0D5" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-beta3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E1E0EDCC-13B3-41D4-8068-05F18FA92AC8" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-beta4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A4F79039-7263-4FB5-A6DB-8650D1F2C55C" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-beta5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4E8739F3-D2B7-4C63-AE14-65B428FBA382" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-beta6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6E254691-CE75-45B8-B0BB-79EAC9C591C2" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-beta7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E70D806B-BC8F-4035-813B-1DCF99836EDE" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-rc1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "34274474-1010-4176-940F-0F602AD8C600" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-rc2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EE24C54E-8C32-42A8-848F-EF9C6CB75FA2" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-rc3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D6BDE732-11D7-492D-9467-9108F774759D" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-rc4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7F02122D-3FA6-4C6A-B3FE-0C2E8613308B" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-rc5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "958CF75F-7BB5-4112-84B0-BBCBB514FD31" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-rc6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E99095F4-148B-4DC5-B199-0150E80672F8" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0-rc7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CD5ECF3-F36E-4BAC-9A41-47C426EF9A98" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FBEFB6B1-7A5F-4C37-8C84-BF92A024A840" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "16EFB096-6739-4952-B921-1CD83E8140F2" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7DA938C8-06F1-4DD7-B26A-4219DDCF8375" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9358CF9C-02BC-4651-B042-DB1EF0904096" }, { "criteria": "cpe:2.3:a:munin-monitoring:munin:2.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "72690B15-9008-4C76-B936-7A6C6835DF19" } ], "operator": "OR" } ] } ]