TildeSlash Monit Authentication Handling Buffer Overflow Vulnerability
BID:10581
Info
TildeSlash Monit Authentication Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 10581 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2004 12:00AM |
| Updated: | Jun 21 2004 12:00AM |
| Credit: | The individual responsible for discovery of this issue is currently unknown. |
| Vulnerable: |
TildeSlash Monit 4.2 TildeSlash Monit 4.1.1 TildeSlash Monit 4.1 TildeSlash Monit 4.0 TildeSlash Monit 3.2 TildeSlash Monit 3.1 TildeSlash Monit 3.0 TildeSlash Monit 2.4.3 TildeSlash Monit 2.4.2 TildeSlash Monit 2.4.1 TildeSlash Monit 2.4 TildeSlash Monit 2.3 TildeSlash Monit 2.2.1 TildeSlash Monit 2.2 TildeSlash Monit 2.1.1 TildeSlash Monit 2.1 TildeSlash Monit 2.0 TildeSlash Monit 1.4.1 TildeSlash Monit 1.4 TildeSlash Monit 1.3.1 TildeSlash Monit 1.3 TildeSlash Monit 1.2 TildeSlash Monit 1.1 TildeSlash Monit 1.0 |
| Not Vulnerable: |
TildeSlash Monit 4.3 Beta 3 TildeSlash Monit 4.3 Beta 2 TildeSlash Monit 4.2.1 |
Discussion
TildeSlash Monit Authentication Handling Buffer Overflow Vulnerability
It is reported that TildeSlash Monit is vulnerable to a buffer overflow vulnerability during authentication handling. This issue arises due to a failure of the affected application to properly handle user-supplied strings when copying them into finite stack-based buffers.
Successful exploitation of this issue allows an attacker to execute arbitrary code as the superuser; facilitating unauthorized access and privilege escalation.
It is reported that TildeSlash Monit is vulnerable to a buffer overflow vulnerability during authentication handling. This issue arises due to a failure of the affected application to properly handle user-supplied strings when copying them into finite stack-based buffers.
Successful exploitation of this issue allows an attacker to execute arbitrary code as the superuser; facilitating unauthorized access and privilege escalation.
Exploit / POC
TildeSlash Monit Authentication Handling Buffer Overflow Vulnerability
The following exploit has been provided:
The following exploit has been provided:
Solution / Fix
TildeSlash Monit Authentication Handling Buffer Overflow Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
TildeSlash Monit 3.0
TildeSlash Monit 3.1
TildeSlash Monit 3.2
TildeSlash Monit 4.0
TildeSlash Monit 4.1
TildeSlash Monit 4.1.1
TildeSlash Monit 4.2
Solution:
The vendor has released an upgrade dealing with this issue.
TildeSlash Monit 3.0
-
TildeSlash monit-4.2.1.tar.gz
http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
TildeSlash Monit 3.1
-
TildeSlash monit-4.2.1.tar.gz
http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
TildeSlash Monit 3.2
-
TildeSlash monit-4.2.1.tar.gz
http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
TildeSlash Monit 4.0
-
TildeSlash monit-4.2.1.tar.gz
http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
TildeSlash Monit 4.1
-
TildeSlash monit-4.2.1.tar.gz
http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
TildeSlash Monit 4.1.1
-
TildeSlash monit-4.2.1.tar.gz
http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
TildeSlash Monit 4.2
-
TildeSlash monit-4.2.1.tar.gz
http://www.tildeslash.com/monit/dist/monit-4.2.1.tar.gz
References
TildeSlash Monit Authentication Handling Buffer Overflow Vulnerability
References:
References:
- Monit Product Page (TildeSlash)