CVE-2012-2103

munin - Arbitrary File Write via Symlink Attack on Temporary Files

Title source: llm
STIX 2.1

Description

The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

References (9)

Core 9
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1622-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74884
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/51218
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/04/16/6
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2012/04/16/5
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/48859
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53031
Issue Tracking x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=812889

Scores

EPSS 0.0033
EPSS Percentile 24.7%

Details

CWE
CWE-59
Status published
Products (1)
munin-monitoring/munin 1.4.5
Published Aug 26, 2012
Tracked Since Feb 18, 2026