Ganglia 3.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by host_view.php and certain other files.
{
"binaries": [
{
"binary_name": "ganglia-monitor",
"binary_version": "3.6.0-1ubuntu2"
},
{
"binary_name": "ganglia-monitor-python",
"binary_version": "3.6.0-1ubuntu2"
},
{
"binary_name": "gmetad",
"binary_version": "3.6.0-1ubuntu2"
},
{
"binary_name": "libganglia1",
"binary_version": "3.6.0-1ubuntu2"
}
]
}
{
"binaries": [
{
"binary_name": "ganglia-monitor",
"binary_version": "3.6.0-6ubuntu4"
},
{
"binary_name": "ganglia-monitor-python",
"binary_version": "3.6.0-6ubuntu4"
},
{
"binary_name": "gmetad",
"binary_version": "3.6.0-6ubuntu4"
},
{
"binary_name": "libganglia1",
"binary_version": "3.6.0-6ubuntu4"
}
]
}
{
"binaries": [
{
"binary_name": "ganglia-monitor",
"binary_version": "3.6.0-7ubuntu2"
},
{
"binary_name": "ganglia-monitor-python",
"binary_version": "3.6.0-7ubuntu2"
},
{
"binary_name": "gmetad",
"binary_version": "3.6.0-7ubuntu2"
},
{
"binary_name": "libganglia1",
"binary_version": "3.6.0-7ubuntu2"
}
]
}