Bug#668536: [Packaging] Bug#668536: munin: predictable tmpfile location /tmp/munin-cgi-tmp

2012-04-13 Thread Holger Levsen
tags 668536 + upstream thanks Hi Helmut, many thanks for filing this bug report! On Donnerstag, 12. April 2012, Helmut Grohne wrote: > /usr/lib/cgi-bin/munin-cgi-graph uses predictable filenames in /tmp > which might allow privilege escalation to www-data or denial of serving > graphs. The filen

Bug#668536: munin: predictable tmpfile location /tmp/munin-cgi-tmp

2012-04-12 Thread Helmut Grohne
Package: munin Version: 2.0~rc4-1 Severity: important Tags: security /usr/lib/cgi-bin/munin-cgi-graph uses predictable filenames in /tmp which might allow privilege escalation to www-data or denial of serving graphs. The filenames always start with /tmp/munin-cgi-graph/. At the moment this issue