Your submission was sent successfully! Close

USN-3971-1: Monit vulnerabilities

8 May 2019

Several security issues were fixed in Monit



  • monit - utility for monitoring and managing daemons or similar programs


Zack Flack discovered that Monit incorrectly handled certain input. A remote
authenticated user could exploit this to conduct cross-site scripting (XSS)
attacks. (CVE-2019-11454)

Zack Flack discovered a buffer overread when Monit decoded certain crafted URLs.
An attacker could exploit this to leak potentially sensitive information.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 19.04
Ubuntu 18.10

In general, a standard system update will make all the necessary changes.

Related notices