Vulnerability Details CVE-2012-3512
Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to execute arbitrary code by replacing a state file, as demonstrated using the smart_ plugin.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.8%
CVSS Severity
CVSS v2 Score 7.2
Products affected by CVE-2012-3512
-
cpe:2.3:a:munin-monitoring:munin:2.0-beta1
-
cpe:2.3:a:munin-monitoring:munin:2.0-beta2
-
cpe:2.3:a:munin-monitoring:munin:2.0-beta3
-
cpe:2.3:a:munin-monitoring:munin:2.0-beta4
-
cpe:2.3:a:munin-monitoring:munin:2.0-beta5
-
cpe:2.3:a:munin-monitoring:munin:2.0-beta6
-
cpe:2.3:a:munin-monitoring:munin:2.0-beta7
-
cpe:2.3:a:munin-monitoring:munin:2.0-rc1
-
cpe:2.3:a:munin-monitoring:munin:2.0-rc2
-
cpe:2.3:a:munin-monitoring:munin:2.0-rc3
-
cpe:2.3:a:munin-monitoring:munin:2.0-rc4
-
cpe:2.3:a:munin-monitoring:munin:2.0-rc5
-
cpe:2.3:a:munin-monitoring:munin:2.0-rc6
-
cpe:2.3:a:munin-monitoring:munin:2.0-rc7
-
cpe:2.3:a:munin-monitoring:munin:2.0.0
-
cpe:2.3:a:munin-monitoring:munin:2.0.1
-
cpe:2.3:a:munin-monitoring:munin:2.0.2
-
cpe:2.3:a:munin-monitoring:munin:2.0.3
-
cpe:2.3:a:munin-monitoring:munin:2.0.4
-
cpe:2.3:a:munin-monitoring:munin:2.0.5