CVE-2002-1663: Input Validation
Published Dec 31, 2002
·Updated
The PostMethod function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of service (crash) via a POST request with an invalid or missing Content-Length header value.
Affected Software
1 affected component
Monkey-project Monkey<=0.1.1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
May 19, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1663?
CVE-2002-1663 has a severity rating indicating it can cause a denial of service by crashing the affected Monkey HTTP Daemon.
2
How do I fix CVE-2002-1663?
To fix CVE-2002-1663, update the Monkey HTTP Daemon to version 0.5.1 or later.
3
Which versions of Monkey HTTP Daemon are affected by CVE-2002-1663?
Monkey HTTP Daemon versions prior to 0.5.1 are affected by CVE-2002-1663.
4
What type of attack is described by CVE-2002-1663?
CVE-2002-1663 describes a remote denial of service attack via malformed POST requests.
5
Where can I find more information about CVE-2002-1663?
More information about CVE-2002-1663 can be found in various security advisories and changelogs for Monkey HTTP Daemon.