PT-2014-6416 · Monkey · Monkey Http Server

Matthew Daley

·

Published

2014-08-26

·

Updated

2020-03-26

·

CVE-2014-5336

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Monkey HTTP Server versions prior to 1.5.3
Description The issue allows remote attackers to cause a denial of service by consuming file descriptors via an HTTP request that triggers an error message, when the File Descriptor Table (FDT) is enabled and custom error messages are set.
Recommendations For versions prior to 1.5.3, update to version 1.5.3 or later to resolve the issue. As a temporary workaround, consider disabling the File Descriptor Table (FDT) or custom error messages to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-5336

Affected Products

Monkey Http Server