PT-2014-6416 · Monkey · Monkey Http Server

Matthew Daley

·

Publicado

2014-08-26

·

Atualizado

2020-03-26

·

CVE-2014-5336

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Monkey HTTP Server versions prior to 1.5.3
Description The issue allows remote attackers to cause a denial of service by consuming file descriptors via an HTTP request that triggers an error message, when the File Descriptor Table (FDT) is enabled and custom error messages are set.
Recommendations For versions prior to 1.5.3, update to version 1.5.3 or later to resolve the issue. As a temporary workaround, consider disabling the File Descriptor Table (FDT) or custom error messages to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-5336

Produtos afetados

Monkey Http Server