A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also cause a denial of service (application outage).
{ "vanir_signatures": [ { "signature_type": "Function", "signature_version": "v1", "source": "https://bitbucket.org/tildeslash/monit@f12d0cdb42d4e74dffe1525d4062c815c48ac57a", "deprecated": false, "id": "CVE-2019-11455-964021e3", "target": { "function": "Util_urlDecode", "file": "src/util.c" }, "digest": { "length": 417.0, "function_hash": "93992887670432761616107281068180192984" } }, { "signature_type": "Line", "signature_version": "v1", "source": "https://bitbucket.org/tildeslash/monit@f12d0cdb42d4e74dffe1525d4062c815c48ac57a", "deprecated": false, "id": "CVE-2019-11455-f79bd834", "target": { "file": "src/util.c" }, "digest": { "line_hashes": [ "336792216971483575453435551836204467274", "291712273761895760649981696046002910704", "271180010610417258655129962113380495898", "21114216790731638776552251915180379568", "173822145611965365697731601117605934289", "245280868408692416270473546290603669879", "242862724403075143428749160003221515339", "298734385230047532110796783583358199549", "217832284105747072654599295948154493272", "284458092717974091187784453750759614001", "99362352307682091576341187826044176903", "144914216189621785524832115774637432358", "156514795832395084577171720215568981037", "204684603920824327899377881952475827354", "311343363071435061989086714180242758086", "272225639610348821859421113697663549549", "60787199865810157298384129240791586496", "334397499546725008374277679329106001896", "81251255236040120734927710176480296484", "140763349542358092626072794061719663411", "331578764451842713949460228859657056635", "225615824364547026479931068946884039306" ], "threshold": 0.9 } } ] }