Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Fedora 23: Security Advisory for Monitorix XSS and DoS Threats

fedora
Calendar Grey November 19, 2015
Scroller Fedora
This patch update resolves vulnerabilities associated with XSS and DoS in Monitorix for Fedora 23, bolstering user security substantially.
This is a maintenance release that mainly fixes a Document Object Model (DOM)-based cross-site scripting (XSS) vulnerability in the monitorix.cgi file

Summary

Monitorix is a free, open source, lightweight system monitoring tool designed

to monitor as many services and system resources as possible. It has been

created to be used under production Linux/UNIX servers, but due to its

simplicity and small size may also be used on embedded devices as well.

Update Information:

This is a maintenance release that mainly fixes a Document Object Model (DOM)-based cross-site scripting (XSS) vulnerability in the monitorix.cgi file. Such vulnerability is by injection a JS code in the when parameter of the URL shown after generating the graphs. Additionally, a potential denial of service (DoS) issue was discovered in the same when parameter of the URL which could lead in the creation of an enormous amount of .png files in the imgs directory of the server.

Change Log

References


[ 1 ] Bug #1281979 - monitorix-3.8.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1281979

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update monitorix' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: monitorix
Product: Fedora 23
Version: 3.8.1
Release: 1.fc23
Summary: A free, open source, lightweight system monitoring tool

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.