漏洞信息详情
多个Monit管理界面远程漏洞
漏洞简介
Monit 1.4至4.2版本的管理界面存在基于堆栈的缓冲区溢出漏洞。远程攻击者借助超长用户名执行任意命令。
漏洞公告
Netwosix Linux has released advisory LNSA-#2004-0008 and fixes for the off-by-one error and the stack overflow in the authentication functionality. Please see the attached advisory for more information. Gentoo has released updates to address this issue, which may be applied with the following commands: emerge sync emerge -pv ">=app-admin/monit-4.2.1" emerge ">=app-admin/monit-4.2.1" The vendor has released fixes to address these issues: TildeSlash Monit 3.0
- TildeSlash monit-4.2.1.tar.gz http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
- TildeSlash monit-4.2.1.tar.gz http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
- TildeSlash monit-4.2.1.tar.gz http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
- TildeSlash monit-4.2.1.tar.gz http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
- TildeSlash monit-4.2.1.tar.gz http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
- TildeSlash monit-4.2.1.tar.gz http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
- TildeSlash monit-4.2.1.tar.gz http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
- TildeSlash monit-4.3-beta3.tar.gz http://www.tildeslash.com/monit/beta/monit-4.3-beta3.tar.gz
参考网址
来源: BID 名称: 10051 链接:http://www.securityfocus.com/bid/10051 来源: SECUNIA 名称: 11304 链接:http://secunia.com/advisories/11304 来源: BUGTRAQ 名称: 20040405 Advisory: Multiple Vulnerabilities in Monit 链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108119149103696&w=2 来源: XF 名称: monit-offbyone-bo(15735) 链接:http://xforce.iss.net/xforce/xfdb/15735 来源: OSVDB 名称: 4981 链接:http://www.osvdb.org/4981
受影响实体
- Tildeslash Monit:4.3_beta_2<!--2000-1-1-->
- Tildeslash Monit:4.2<!--2000-1-1-->
- Tildeslash Monit:4.0<!--2000-1-1-->
- Tildeslash Monit:4.1<!--2000-1-1-->
- Tildeslash Monit:4.1.1<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...