|
|
|
![]() |
Vulnerability Note VU#623854Monit fails to properly handle negative Content-Length fieldsOverviewMonit fails to properly handle HTTP requests containing a negative Content-Length field.I. DescriptionMonit is a utility to monitor system processes, files, directories, devices, and remote hosts. It provides a web-based interface that can be used to access the Monit server. When processing HTTP requests, Monit fails to properly sanitize the Content-Length field. By supplying a negative value for the Content-Length field of an HTTP request, an unauthenticated, remote attacker could cause the Monit daemon to crash.II. ImpactA remote, unauthenticated attacker could cause the Monit daemon to crash, resulting in a denial-of-service condition.III. SolutionUpgradeUpgrade to Monit version 4.1.1 or later.
References
This vulnerability was reported by Evgeny Legerov of S-Quadra. This document was written by Damon Morda.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||