Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 31: FEDORA-2020-9c19202d55 Critical: Monit Buffer Overflow

fedora
Calendar Grey March 12, 2020
Dist Fedora Esm H88
Oversee and protect operations using monit 5.26.0, safeguarding against potential vulnerabilities by upgrading your Fedora platform.
Update to 5.26.0 (includes security fix for CVE-2019-11454 and CVE-2019-11455)

Summary

monit is a utility for managing and monitoring, processes, files, directories

and devices on a UNIX system. Monit conducts automatic maintenance and repair

and can execute meaningful causal actions in error situations.

Update to 5.26.0 (includes security fix for CVE-2019-11454 and CVE-2019-11455)

* Tue Mar 3 2020 Stewart Adam - 5.26.0-1

- Update to 5.26.0

* Thu Jul 25 2019 Fedora Release Engineering - 5.25.1-7

- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild

[ 1 ] Bug #1663929 - monit: Use-after-free in function _handleEvent()

https://bugzilla.redhat.com/show_bug.cgi?id=1663929

[ 2 ] Bug #1691391 - monit: Multiple issues fixed in 5.25.3

https://bugzilla.redhat.com/show_bug.cgi?id=1691391

[ 3 ] Bug #1702637 - CVE-2019-11455 monit: buffer over-read in function Util_urlDecode in util.c

https://bugzilla.redhat.com/show_bug.cgi?id=1702637

[ 4 ] Bug #1702682 - CVE-2019-11454 monit: cross-site scripting (XSS) in http/cervlet.c

https://bugzilla.redhat.com/show_bug.cgi?id=1702682

[ 5 ] Bug #1695987 - monit: Multiple vulnerabilities fixed in monit 5.25.3

https://bugzilla.redhat.com/show_bug.cgi?id=1695987

su -c 'dnf upgrade --advisory FEDORA-2020-9c19202d55' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 31
Version: 5.26.0
Release: 1.fc31
Summary: Manages and monitors processes, files, directories and devices

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here