CVE-2019-13486: Buffer Overflow
Published Aug 27, 2019
·Updated
In Xymon through 4.3.28, a stack-based buffer overflow exists in the status-log viewer component because of expansion in svcstatus.c.
Affected Software
2 affected components
Xymon xymon<=4.3.28
Debian Debian Linux=8.0
Event History
Aug 27, 2019
CVE Published
via MITRE·04:01 PM
Data Sourced
via MITRE·04:01 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13486?
CVE-2019-13486 has a high severity level due to the stack-based buffer overflow vulnerability that can lead to remote code execution.
2
How do I fix CVE-2019-13486?
To fix CVE-2019-13486, update Xymon to version 4.3.29 or later to patch the vulnerability.
3
Which versions of Xymon are affected by CVE-2019-13486?
CVE-2019-13486 affects Xymon versions up to and including 4.3.28.
4
What causes the vulnerability in CVE-2019-13486?
The vulnerability in CVE-2019-13486 is caused by improper handling of expansion in the svcstatus.c component.
5
Is CVE-2019-13486 specific to any operating system?
Yes, CVE-2019-13486 is specifically noted to affect Debian GNU/Linux 8.0 when running Xymon version 4.3.28.