CVE-2013-1771: High severity monkey project vulnerability
Published Nov 7, 2019
·Updated
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
Affected Software
2 affected components
debian/monkey
Monkey-project Monkey
Event History
Nov 7, 2019
CVE Published
via MITRE·10:05 PM
Data Sourced
via MITRE·10:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2013-1771?
CVE-2013-1771 has been classified as a medium severity vulnerability due to exposure of sensitive log information.
2
How do I fix CVE-2013-1771?
To fix CVE-2013-1771, you should configure the permissions of the log file to ensure it is not world-readable.
3
What is the impact of CVE-2013-1771?
The impact of CVE-2013-1771 is that sensitive information may be exposed to unauthorized users via the world-readable log file.
4
Which versions of Monkey are affected by CVE-2013-1771?
CVE-2013-1771 affects all versions of the Monkey web server that produce the world-readable log.
5
Is CVE-2013-1771 specific to any operating system?
Yes, CVE-2013-1771 is specific to the Gentoo operating system configuration of the Monkey web server.