CVE-2004-1897: Medium severity Tildeslash Monit vulnerability
Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authentication request without a password, which causes Monit to decrement a null pointer and perform an out-of-bounds read.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1897?
CVE-2004-1897 is classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2004-1897?
To fix CVE-2004-1897, upgrade Monit to a version later than 4.2 that addresses this vulnerability.
Which versions of Monit are affected by CVE-2004-1897?
CVE-2004-1897 affects Monit versions 1.4 through 4.2.
What type of attack does CVE-2004-1897 facilitate?
CVE-2004-1897 allows remote attackers to cause a denial of service by sending a malformed authentication request.
Is there a workaround for CVE-2004-1897 if upgrading is not possible?
A possible workaround for CVE-2004-1897 includes restricting access to the Monit administration interface to trusted IP addresses.