vendor:
Monkey HTTPD
by:
Doug Prostko
3,3
CVSS
LOW
Denial of Service
N/A
CWE
Product Name: Monkey HTTPD
Affected Version From: 1.1.1
Affected Version To: 1.1.1
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: GNU/Linux
2013
Monkey HTTPD 1.1.1 – Denial of Service Vulnerability
A bug discovered in Monkey's HTTP parser allows an attacker to cause a segmentation fault in one of the daemon's threads using a specially crafted request containing a null byte. An attacker can crash all the available threads by sending the specially crafted request multiple times, rendering the server useless for legitimate users.
Mitigation:
This vulnerability has been fixed for the 1.2.0 release.