CVE-2013-3724: Input Validation
Published Jul 31, 2013
·Updated
The mkrequestheaderprocess function in mkrequest.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service outage) via a '\0' character in an HTTP request.
Affected Software
1 affected component
Monkey-project Monkey=1.1.1
Remediation
Patch Available
Event History
Jul 31, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3724?
CVE-2013-3724 has a severity rating of medium as it can lead to denial of service due to thread crashes.
2
How do I fix CVE-2013-3724?
To fix CVE-2013-3724, upgrade to a later version of Monkey that is not affected by this vulnerability.
3
What specific component is affected by CVE-2013-3724?
CVE-2013-3724 affects the mk_request_header_process function in mk_request.c within Monkey version 1.1.1.
4
What type of attack does CVE-2013-3724 enable?
CVE-2013-3724 enables remote attackers to launch denial of service attacks by sending specially crafted HTTP requests.
5
Is this vulnerability exploitable from the outside?
Yes, CVE-2013-3724 can be exploited by remote attackers, making it a serious concern for exposed servers.