USN-3971-1: Monit vulnerabilities
Zack Flack discovered that Monit incorrectly handled certain input. A remote authenticated user could exploit this to conduct cross-site scripting (XSS) attacks. (CVE-2019-11454) Zack Flack discovered a buffer overread when Monit decoded certain crafted URLs. An attacker could exploit this to leak potentially sensitive information. (CVE-2019-11455)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-3971-1?
The severity of USN-3971-1 is considered medium due to its potential for cross-site scripting (XSS) attacks.
How do I fix USN-3971-1?
To fix USN-3971-1, update Monit to version 1:5.25.2-3ubuntu0.1 for Ubuntu 19.04 or 1:5.25.2-1ubuntu0.1 for Ubuntu 18.10.
Who identified the vulnerabilities in USN-3971-1?
The vulnerabilities in USN-3971-1 were discovered by Zack Flack.
What types of vulnerabilities are addressed in USN-3971-1?
USN-3971-1 addresses cross-site scripting (XSS) and a buffer overread vulnerability.
Which versions of Ubuntu are affected by USN-3971-1?
USN-3971-1 affects Ubuntu 19.04 and Ubuntu 18.10.