|
|
|
![]() |
Vulnerability Note VU#206382Monit fails to properly handle overly long HTTP requestsOverviewMonit is vulnerable to a buffer overflow when processing overly long HTTP requests.I. DescriptionMonit is a utility to monitor system processes, files, directories, devices, and remote hosts. It provides a web-based interface that can be used to access the Monit server. There is a buffer overflow vulnerability in the way Monit handles HTTP requests. By supplying an overly long HTTP request, an unauthenticated, remote attacker could execute arbitrary code with privileges of the vulnerable process.II. ImpactA remote, unauthenticated attacker could execute arbitrary code on the vulnerable system with privileges of the vulnerable process.III. SolutionUpgradeUpgrade to Monit version 4.1.1 or later.
References
This vulnerability was reported by Evgeny Legerov of S-Quadra. This document was written by Damon Morda.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||