CVE-2019-11455: Canonical Ubuntu Linux

High severity, CVSS 8.1. EPSS: 3.1% chance of exploitation in the next 30 days.

A buffer over-read in Util_urlDecode in util.c in Tildeslash Monit before 5.25.3 allows a remote authenticated attacker to retrieve the contents of adjacent memory via manipulation of GET or POST parameters. The attacker can also cause a denial of service (application outage).

Affected products

  • Canonical Ubuntu Linux: version 18.10 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only
  • Fedoraproject Fedora: version 31 only; version 32 only
  • Tildeslash Monit: before 5.25.3 (fixed in 5.25.3)

Published 2019-04-22. Last modified 2026-06-17.