CVE-2014-5336: Input Validation
Monkey HTTP Server before 1.5.3, when the File Descriptor Table (FDT) is enabled and custom error messages are set, allows remote attackers to cause a denial of service (file descriptor consumption) via an HTTP request that triggers an error message.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5336?
CVE-2014-5336 has been classified as a high severity vulnerability due to its potential to cause a denial of service by consuming file descriptors.
How do I fix CVE-2014-5336?
To remediate CVE-2014-5336, it is recommended to upgrade to Monkey HTTP Server version 1.5.3 or later, as this version includes fixes.
What versions are affected by CVE-2014-5336?
CVE-2014-5336 affects all versions of Monkey HTTP Server prior to 1.5.3.
What does CVE-2014-5336 exploit?
CVE-2014-5336 exploits the File Descriptor Table when enabled alongside custom error messages, allowing remote attackers to trigger a denial of service.
Can CVE-2014-5336 impact server performance?
Yes, CVE-2014-5336 can significantly impact server performance by exhausting available file descriptors, leading to service availability issues.