The administration interface in Monit 1.4 through 4.2 allows remote attackers to cause an off-by-one overflow via a POST that contains 1024 bytes.
| Software | From | Fixed in |
|---|---|---|
| tildeslash / monit | 1.4 | 1.4.x |
| tildeslash / monit | 4.3_beta_2 | 4.3_beta_2.x |
| tildeslash / monit | 3.2 | 3.2.x |
| tildeslash / monit | 3.0 | 3.0.x |
| tildeslash / monit | 4.1 | 4.1.x |
| tildeslash / monit | 3.1 | 3.1.x |
| tildeslash / monit | 4.1.1 | 4.1.1.x |
| tildeslash / monit | 4.2 | 4.2.x |
| tildeslash / monit | 4.0 | 4.0.x |