CVE-2017-6188: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Munin-Monitoring Munin: before 2.0.30.1 (fixed in 2.0.30.1); from 2.1.0, before 2.999.9 (fixed in 2.999.9)

Published 2017-02-22. Last modified 2026-06-17.