CVE-2019-13273: Debian Linux

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

In Xymon through 4.3.28, a buffer overflow vulnerability exists in the csvinfo CGI script. The overflow may be exploited by sending a crafted GET request that triggers an sprintf of the srcdb parameter.

Affected products

  • Debian Debian Linux: version 8.0 only
  • Xymon Xymon: up to and including 4.3.28

Published 2019-08-27. Last modified 2026-06-17.