CVE-2004-0276: Input Validation
Published Sep 1, 2004
·Updated
The getrealstring function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field.
Affected Software
11 affected components
Monkey-project Monkey<=0.8.1
Monkey-project Monkey=0.1.1
Monkey-project Monkey=0.5.2
Monkey-project Monkey=0.6.0
Monkey-project Monkey=0.6.1
Monkey-project Monkey=0.6.2
Monkey-project Monkey=0.6.3
Monkey-project Monkey=0.7.0
Monkey-project Monkey=0.7.1
Monkey-project Monkey=0.7.2
Monkey-project Monkey=0.8.0
Remediation
Patch Available
Event History
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0276?
CVE-2004-0276 is classified as a denial of service vulnerability.
2
How do I fix CVE-2004-0276?
To mitigate CVE-2004-0276, upgrade to Monkey HTTP Daemon version 0.8.2 or later.
3
What software is affected by CVE-2004-0276?
CVE-2004-0276 affects Monkey HTTP Daemon versions 0.8.1 and earlier, including versions 0.1.1 to 0.8.1.
4
What type of attack is described in CVE-2004-0276?
CVE-2004-0276 vulnerability allows remote attackers to crash the server by sending specially crafted HTTP requests.
5
How can I determine if my system is vulnerable to CVE-2004-0276?
Check if you are using Monkey HTTP Daemon version 0.8.1 or earlier, as these versions are susceptible to CVE-2004-0276.