vendor:
Monit
by:
Nilanjan De, Abhisek Datta
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Monit
Affected Version From: <= 4.2
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2004
TildeSlash Monit Buffer Overflow Vulnerability
This vulnerability allows an attacker to execute arbitrary code as the superuser, leading to unauthorized access and privilege escalation. The exploit takes advantage of the insecure handling of usernames in Basic Authentication information to control the execution instruction pointer (EIP) and execute the payload.
Mitigation:
The vendor should release a patch to fix the buffer overflow vulnerability. It is recommended to update to the latest version of TildeSlash Monit.