Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to execute arbitrary code by replacing a state file, as demonstrated using the smart_ plugin.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Munin 不安全文件权限漏洞
Vulnerability Description
Munin是一套网络资源监控工具。该工具可监控核心系统资源,包括内存、磁盘、CPU占用、服务器应用等。 Munin 2.0.6之前版本中存在漏洞,该漏洞源于存储插件状态文件以root身份运行在同组可写目录作为非root插件。本地攻击者利用该漏洞通过替换状态文件如使用smart_插件,执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A