Overview
Monit is vulnerable to a buffer overflow when processing overly long HTTP requests.
Description
Monit is a utility to monitor system processes, files, directories, devices, and remote hosts. It provides a web-based interface that can be used to access the Monit server. There is a buffer overflow vulnerability in the way Monit handles HTTP requests. By supplying an overly long HTTP request, an unauthenticated, remote attacker could execute arbitrary code with privileges of the vulnerable process. |
Impact
A remote, unauthenticated attacker could execute arbitrary code on the vulnerable system with privileges of the vulnerable process. |
Solution
Upgrade Upgrade to Monit version 4.1.1 or later. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported by Evgeny Legerov of S-Quadra.
This document was written by Damon Morda.
Other Information
CVE IDs: | None |
Severity Metric: | 4.78 |
Date Public: | 2004-03-31 |
Date First Published: | 2004-04-06 |
Date Last Updated: | 2004-04-06 14:12 UTC |
Document Revision: | 9 |