Stack-based buffer overflow in Monit 1.4 to 4.1 allows remote attackers to execute arbitrary code via a long HTTP request.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tildeslash | monit | 1.4.1 |
| tildeslash | monit | 2.0 |
| tildeslash | monit | 2.1.1 |
| tildeslash | monit | 2.4.3 |
| tildeslash | monit | 3.1 |
| tildeslash | monit | 2.2 |
| tildeslash | monit | 2.3 |
| tildeslash | monit | 3.0 |
| tildeslash | monit | 1.4 |
| tildeslash | monit | 2.4.1 |
| tildeslash | monit | 3.2 |
| tildeslash | monit | 2.1 |
| tildeslash | monit | 4.0 |
| tildeslash | monit | 2.2.1 |
| tildeslash | monit | 2.4 |
| tildeslash | monit | 4.1 |
| tildeslash | monit | 2.4.2 |
Monit 1.4 to 4.1 allows remote attackers to cause a denial of service (daemon crash) via an HTTP POST request with a negative Content-Length field.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tildeslash | monit | 1.4.1 |
| tildeslash | monit | 2.0 |
| tildeslash | monit | 2.1.1 |
| tildeslash | monit | 2.4.3 |
| tildeslash | monit | 3.1 |
| tildeslash | monit | 2.2 |
| tildeslash | monit | 2.3 |
| tildeslash | monit | 3.0 |
| tildeslash | monit | 1.4 |
| tildeslash | monit | 2.4.1 |
| tildeslash | monit | 3.2 |
| tildeslash | monit | 2.1 |
| tildeslash | monit | 4.0 |
| tildeslash | monit | 2.2.1 |
| tildeslash | monit | 2.4 |
| tildeslash | monit | 4.1 |
| tildeslash | monit | 2.4.2 |
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute arbitrary code via a long username.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tildeslash | monit | 3.0 |
| tildeslash | monit | 4.1.1 |
| tildeslash | monit | 4.2 |
| tildeslash | monit | 4.3_beta_2 |
| tildeslash | monit | 1.4 |
| tildeslash | monit | 3.2 |
| tildeslash | monit | 4.0 |
| tildeslash | monit | 3.1 |
| tildeslash | monit | 4.1 |
The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tildeslash | monit | 3.0 |
| tildeslash | monit | 4.1.1 |
| tildeslash | monit | 4.2 |
| tildeslash | monit | 4.3_beta_2 |
| tildeslash | monit | 1.4 |
| tildeslash | monit | 3.2 |
| tildeslash | monit | 4.0 |
| tildeslash | monit | 3.1 |
| tildeslash | monit | 4.1 |