CVE-2013-2163: Input Validation
Published Jun 13, 2014
·Updated
Monkey HTTP Daemon (monkeyd) before 1.2.2 allows remote attackers to cause a denial of service (infinite loop) via an offset equal to the file size in the Range HTTP header.
Affected Software
2 affected components
Monkey-project Monkey<=1.2.1
Monkey-project Monkey=1.2.0
Event History
Jun 13, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-2163?
CVE-2013-2163 is classified as a denial of service vulnerability.
2
How do I fix CVE-2013-2163?
To fix CVE-2013-2163, upgrade to Monkey HTTP Daemon version 1.2.2 or later.
3
What does CVE-2013-2163 affect?
CVE-2013-2163 affects Monkey HTTP Daemon versions prior to 1.2.2.
4
What type of attack can be executed due to CVE-2013-2163?
CVE-2013-2163 allows remote attackers to cause a denial of service via an infinite loop.
5
How does the Range HTTP header relate to CVE-2013-2163?
The vulnerability in CVE-2013-2163 is triggered by an attacker-controlled offset equal to the file size in the Range HTTP header.