Debian Security Advisory
DLA-2855-1 monit -- LTS security update
- Date Reported:
- 27 Dec 2021
- Affected Packages:
- monit
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 927775.
In Mitre's CVE dictionary: CVE-2019-11454, CVE-2019-11455. - More information:
-
Two vulnerabilities were fixed in monit, a utility for monitoring and managing Unix systems.
- CVE-2019-11454
Persistent cross-site scripting in http/cervlet.c
- CVE-2019-11455
Buffer over-read in Util_urlDecode in util.c
For Debian 9 stretch, these problems have been fixed in version 1:5.20.0-6+deb9u2.
We recommend that you upgrade your monit packages.
For the detailed security status of monit please refer to its security tracker page at: https://security-tracker.debian.org/tracker/monit
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
- CVE-2019-11454