CVE-2005-1122: High severity Monkey-project Monkey vulnerability
Published Apr 14, 2005
·Updated
Format string vulnerability in cgi.c for Monkey daemon (monkeyd) before 0.9.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via an HTTP GET request containing double-encoded format string specifiers (aka "double expansion error").
Affected Software
17 affected components
Monkey-project Monkey<=0.9.0
Monkey-project Monkey=0.1.1
Monkey-project Monkey=0.5.2
Monkey-project Monkey=0.6.0
Monkey-project Monkey=0.6.1
Monkey-project Monkey=0.6.2
Monkey-project Monkey=0.6.3
Monkey-project Monkey=0.7.0
Monkey-project Monkey=0.7.1
Monkey-project Monkey=0.7.2
Monkey-project Monkey=0.8.0
Monkey-project Monkey=0.8.1
Monkey-project Monkey=0.8.2
Monkey-project Monkey=0.8.3
Monkey-project Monkey=0.8.4
Monkey-project Monkey=0.8.4-2
Monkey-project Monkey=0.8.5
Remediation
Patch Available
Patch Available
Event History
Apr 14, 2005
CVE Published
04:00 AM
Apr 16, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1122?
CVE-2005-1122 has a high severity level due to the potential for remote code execution and denial of service.
2
How do I fix CVE-2005-1122?
To fix CVE-2005-1122, upgrade to Monkey daemon version 0.9.1 or later.
3
What type of vulnerability is CVE-2005-1122?
CVE-2005-1122 is a format string vulnerability that affects the Monkey HTTP daemon.
4
Who is affected by CVE-2005-1122?
Users running vulnerable versions of the Monkey HTTP Daemon prior to 0.9.1 are affected by CVE-2005-1122.
5
Can CVE-2005-1122 be exploited remotely?
Yes, CVE-2005-1122 can be exploited remotely through crafted HTTP GET requests.