CVE-2019-11455: High severity monit vulnerability
Published Apr 22, 2019
·Updated
A buffer over-read in UtilurlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also cause a denial of service (application outage).
Affected Software
7 affected componentsFixes available
debian/monit
1:5.27.2-11:5.33.0-11:5.34.0-1
Tildeslash Monit<5.25.3
Debian Debian Linux=8.0
Fedoraproject Fedora=31
Fedoraproject Fedora=32
Canonical Ubuntu Linux=18.10
Canonical Ubuntu Linux=19.04
Remediation
Patch Available
Event History
Apr 22, 2019
CVE Published
via MITRE·03:06 PM
Data Sourced
via MITRE·03:06 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:14 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:09 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-11455?
CVE-2019-11455 has a medium severity rating due to its potential for remote exploitation and denial of service.
2
How do I fix CVE-2019-11455?
To fix CVE-2019-11455, update Monit to version 5.27.2 or later.
3
What affected versions are vulnerable to CVE-2019-11455?
CVE-2019-11455 impacts Monit versions prior to 5.25.3.
4
What types of attacks can CVE-2019-11455 facilitate?
CVE-2019-11455 can facilitate buffer over-reads and denial of service attacks.
5
Is CVE-2019-11455 specific to certain operating systems?
CVE-2019-11455 affects multiple operating systems, including Debian, Fedora, and Ubuntu.