Administration interface in Monit 1.4 through 4.2 allows remote attackers to cause a denial of service (segmentation fault) by sending a Basic Authentication request without a password, which causes Monit to decrement a null pointer and perform an out-of-bounds read.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Monit | Tildeslash | 1.4 (including) | 1.4 (including) |
Monit | Tildeslash | 3.0 (including) | 3.0 (including) |
Monit | Tildeslash | 3.1 (including) | 3.1 (including) |
Monit | Tildeslash | 3.2 (including) | 3.2 (including) |
Monit | Tildeslash | 4.0 (including) | 4.0 (including) |
Monit | Tildeslash | 4.1 (including) | 4.1 (including) |
Monit | Tildeslash | 4.1.1 (including) | 4.1.1 (including) |
Monit | Tildeslash | 4.2 (including) | 4.2 (including) |
Monit | Tildeslash | 4.3_beta_2 (including) | 4.3_beta_2 (including) |