oss-sec mailing list archives

Re: [Packaging] Bug#668667: [oss-security] CVE Request (minor) -- Two Munin graphing framework flaws


From: Holger Levsen <holger () layer-acht org>
Date: Thu, 19 Apr 2012 08:29:46 +0200

On Donnerstag, 19. April 2012, Kenyon Ralph wrote:
On Debian, symlinks to enable plugins are installed by default, and an
apache2 configuration is automatically activated. So, on Debian, if
your httpd is publicly-accessible, the munin pages and CGI will be
publicly-accessible.

though on Debian, apache is only accessable on localhost per default.


Current thread: