Updated monit package fixes security vulnerabilities:
Zack Flack discovered that Monit incorrectly handled certain input.
A remote authenticated user could exploit this to conduct cross-site
scripting (XSS) attacks (CVE-2019-11454).
Zack Flack discovered a buffer overread when Monit decoded certain crafted
URLs. An attacker could exploit this to leak potentially sensitive
information (CVE-2019-11455).
- https://bugs.mageia.org/show_bug.cgi?id=25269
- https://ubuntu.com/security/notices/USN-3971-1
- https://www.cve.org/CVERecord?id=CVE-2019-11454
- https://www.cve.org/CVERecord?id=CVE-2019-11455
- 6/core/monit-5.25.3-1.1.mga6
Get the latest Linux and open source security news straight to your inbox.