Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 6: MGASA-2019-0246 Moderate: Monit XSS And Buffer Overread

mageia
Calendar Grey September 6, 2019
Dist Mageia Esm H88
An enhanced monit package resolves serious vulnerabilities in Mageia distributions. Insights into XSS and data exposure threats.
Updated monit package fixes security vulnerabilities: Zack Flack discovered that Monit incorrectly handled certain input

Summary

Updated monit package fixes security vulnerabilities:
Zack Flack discovered that Monit incorrectly handled certain input. A remote authenticated user could exploit this to conduct cross-site scripting (XSS) attacks (CVE-2019-11454).
Zack Flack discovered a buffer overread when Monit decoded certain crafted URLs. An attacker could exploit this to leak potentially sensitive information (CVE-2019-11455).

References

- https://bugs.mageia.org/show_bug.cgi?id=25269

- https://ubuntu.com/security/notices/USN-3971-1

- https://www.cve.org/CVERecord?id=CVE-2019-11454

- https://www.cve.org/CVERecord?id=CVE-2019-11455

Resolution

SRPMS

- 6/core/monit-5.25.3-1.1.mga6

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 06 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0246.html
Type: security
CVE: CVE-2019-11454, CVE-2019-11455

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here