Monit过度超长请求HTTP请求缓冲区泛滥漏洞

admin 2022-07-22 11:51:11 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

Monit过度超长请求HTTP请求缓冲区泛滥漏洞

  • CNNVD编号:CNNVD-200312-348
  • 危害等级: 超危
  • CVE编号: CVE-2003-1083
  • 漏洞类型: 缓冲区溢出
  • 发布时间: 2003-12-31
  • 威胁类型: 远程
  • 更新时间: 2005-10-20
  • 厂        商: tildeslash
  • 漏洞来源: .');">The discovery of t...

漏洞简介

Monit 1.4版本到4.1版本存在基于堆的缓冲区溢出漏洞。远程攻击者可以借助超长HTTP请求执行任意代码。

漏洞公告

The vendor has release Monit 4.1.1 to address this issue in affected versions. Users are advised to upgrade to the latest version as soon as possible. Gentoo has released an advisory GLSA 200403-14 to address this and another issue in Monit. Please see the referenced advisory for more information. Gentoo users may carry out the following commands to upgrade to Monit version 4.2: # emerge sync # emerge -pv ">=app-admin/monit-4.2" # emerge ">=app-admin/monit-4.2" TildeSlash Monit 1.4

  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 1.4.1
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 2.0
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 2.1
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 2.1.1
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 2.2
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 2.2.1
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 2.3
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 2.4
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 2.4.1
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 2.4.2
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 2.4.3
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 3.0
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 3.1
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 3.2
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 4.0
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz
TildeSlash Monit 4.1
  • TildeSlash Monit 4.1.1 http://www.tildeslash.com/monit/dist/monit-4.1.1.tar.gz

参考网址

来源:US-CERT Vulnerability Note: VU#623854 名称: VU#623854 链接:http://www.kb.cert.org/vuls/id/623854 来源: XF 名称: monit-http-bo(13817) 链接:http://xforce.iss.net/xforce/xfdb/13817 来源: BID 名称: 9099 链接:http://www.securityfocus.com/bid/9099 来源: GENTOO 名称: GLSA-200403-14 链接:http://security.gentoo.org/glsa/glsa-200403-14.xml 来源: SECUNIA 名称: 10280 链接:http://secunia.com/advisories/10280 来源: www.tildeslash.com 链接:http://www.tildeslash.com/monit/dist/CHANGES.txt 来源: BUGTRAQ 名称: 20031124 Monit 4.1 HTTP interface multiple security vulnerabilities 链接:http://www.securityfocus.com/archive/1/345417

受影响实体

  • Tildeslash Monit:4.1  
  • Tildeslash Monit:4.0  
  • Tildeslash Monit:3.2  
  • Tildeslash Monit:3.1  
  • Tildeslash Monit:3.0  

补丁

    暂无

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
评论:0   参与:  0