CVE-2013-3843
medium · 6.8Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP header.
6.8
CVSS
20.2%
EPSS (exploit prob.)
97th
EPSS percentile
2014-06-13
Published
AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| monkey-project | monkey | <= 1.2.0 |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2013-06/0015.html
- http://bugs.monkey-project.com/ticket/182
- http://monkey-project.com/Announcements/v1.2.1
- http://secunia.com/advisories/53697
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84755
- https://github.com/monkey/monkey/issues/88
- http://archives.neohapsis.com/archives/bugtraq/2013-06/0015.html
- http://bugs.monkey-project.com/ticket/182
- http://monkey-project.com/Announcements/v1.2.1
- http://secunia.com/advisories/53697
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84755
- https://github.com/monkey/monkey/issues/88
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2013-3843