Vulnerability Name: | CVE-2012-2147 (CCN-78924) | ||||||||||||||||
Assigned: | 2012-04-17 | ||||||||||||||||
Published: | 2012-04-17 | ||||||||||||||||
Updated: | 2017-08-29 | ||||||||||||||||
Summary: | munin-cgi-graph in Munin 2.0 rc4 allows remote attackers to cause a denial of service (disk or memory consumption) via many image requests with large values in the (1) size_x or (2) size_y parameters. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 4.0 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
4.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:U/RC:UR)
| ||||||||||||||||
Vulnerability Type: | CWE-399 | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2012-2147 Source: MLIST Type: UNKNOWN [oss-security] 20120417 Re: CVE Request (minor) -- Two Munin graphing framework flaws Source: CCN Type: oss-sec mailing list, Tue, 17 Apr 2012 23:04:56 -0600 CVE Request (minor) -- Two Munin graphing framework flaws Source: MLIST Type: UNKNOWN [oss-security] 20120417 RE: CVE Request (minor) -- Two Munin graphing framework flaws Source: MLIST Type: UNKNOWN [oss-security] 20120418 Re: CVE Request (minor) -- Two Munin graphing framework flaws Source: MLIST Type: UNKNOWN [oss-security] 20120418 Re: Bug#668667: CVE Request (minor) -- Two Munin graphing framework flaws Source: MLIST Type: UNKNOWN [oss-security] 20120419 Re: [Packaging] Bug#668667: CVE Request (minor) -- Two Munin graphing framework flaws Source: MLIST Type: UNKNOWN [oss-security] 20120427 Re: Bug#668667: CVE Request (minor) -- Two Munin graphing framework flaws Source: MLIST Type: UNKNOWN [oss-security] 20120429 Re: Bug#668667: CVE Request (minor) -- Two Munin graphing framework flaws Source: XF Type: UNKNOWN munin-image-requests-dos(78924) Source: XF Type: UNKNOWN munin-image-requests-dos(78924) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |