Lucene search

K
cveMitreCVE-2013-3843
HistoryJun 13, 2014 - 2:55 p.m.

CVE-2013-3843

2014-06-1314:55:12
CWE-119
mitre
web.nvd.nist.gov
104
cve-2013-3843
buffer overflow
http daemon
monkey
denial of service
remote code execution
security vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

High

EPSS

0.345

Percentile

97.2%

Stack-based buffer overflow in the mk_request_header_process function in mk_request.c in Monkey HTTP Daemon (monkeyd) before 1.2.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP header.

Affected configurations

Nvd
Node
monkey-projectmonkeyRange1.2.0
VendorProductVersionCPE
monkey-projectmonkey*cpe:2.3:a:monkey-project:monkey:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

8

Confidence

High

EPSS

0.345

Percentile

97.2%