In Xymon through 4.3.28, a stack-based buffer overflow vulnerability exists in the alert acknowledgment CGI tool because of expansion in acknowledge.c.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/svn2github/xymon/blob/master/branches/4.3.28/web/acknowledge.c | third party advisory |
https://lists.debian.org/debian-lts-announce/2019/08/msg00032.html | third party advisory mailing list |
https://lists.xymon.com/archive/2019-July/046570.html | mailing list exploit vendor advisory |