CVE-2019-13273: Buffer Overflow
Published Aug 27, 2019
·Updated
In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.
Affected Software
2 affected components
Xymon xymon<=4.3.28
Debian Debian Linux=8.0
Event History
Aug 27, 2019
CVE Published
via MITRE·04:52 PM
Data Sourced
via MITRE·04:52 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13273?
CVE-2019-13273 is classified as a medium severity vulnerability due to its potential to cause a buffer overflow.
2
How do I fix CVE-2019-13273?
To fix CVE-2019-13273, upgrade to the latest version of Xymon beyond 4.3.28 or apply the relevant patches provided by your distribution.
3
What causes the vulnerability CVE-2019-13273?
CVE-2019-13273 is caused by a buffer overflow in the csvinfo CGI script triggered by a crafted GET request.
4
Which software is affected by CVE-2019-13273?
CVE-2019-13273 affects Xymon versions up to and including 4.3.28 and Debian GNU/Linux version 8.0.
5
Can CVE-2019-13273 be exploited remotely?
Yes, CVE-2019-13273 can be exploited remotely by sending specially crafted HTTP GET requests.