Monkey HTTP Daemon Excessive POST Data Buffer Overflow Vulnerability
BID:7202
Info
Monkey HTTP Daemon Excessive POST Data Buffer Overflow Vulnerability
| Bugtraq ID: | 7202 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 24 2003 12:00AM |
| Updated: | Mar 24 2003 12:00AM |
| Credit: | Discovery is credited to Matthew Murphy. |
| Vulnerable: |
Monkey Monkey HTTP Daemon 0.6.1 Monkey Monkey HTTP Daemon 0.6 Monkey Monkey HTTP Daemon 0.5.1 Monkey Monkey HTTP Daemon 0.5 Monkey Monkey HTTP Daemon 0.4.2 Monkey Monkey HTTP Daemon 0.4.1 Monkey Monkey HTTP Daemon 0.4 |
| Not Vulnerable: |
Monkey Monkey HTTP Daemon 0.6.2 |
Discussion
Monkey HTTP Daemon Excessive POST Data Buffer Overflow Vulnerability
Monkey HTTP Daemon is prone to a boundary condition error. This condition occurs when the server attempts to handle excessive HTTP POST data. Exploitation could allow a remote attacker to corrupt sensitive regions of memory with attacker-supplied values, resulting in code execution. Exploitation attempts may also result in a denial of service.
Monkey HTTP Daemon is prone to a boundary condition error. This condition occurs when the server attempts to handle excessive HTTP POST data. Exploitation could allow a remote attacker to corrupt sensitive regions of memory with attacker-supplied values, resulting in code execution. Exploitation attempts may also result in a denial of service.
Exploit / POC
Monkey HTTP Daemon Excessive POST Data Buffer Overflow Vulnerability
The following proof-of-concept was provided by Matthew Murphy <[email protected]>:
The following proof-of-concept was provided by Matthew Murphy <[email protected]>:
Solution / Fix
Monkey HTTP Daemon Excessive POST Data Buffer Overflow Vulnerability
Solution:
The vendor has released version 0.6.2 to resolve this issue.
Gentoo has released an advisory for Gentoo Linux users. Gentoo users are advised to issue the following commands to update vulnerable systems:
emerge sync
emerge monkeyd
emerge clean
Monkey Monkey HTTP Daemon 0.4
Monkey Monkey HTTP Daemon 0.4.1
Monkey Monkey HTTP Daemon 0.4.2
Monkey Monkey HTTP Daemon 0.5
Monkey Monkey HTTP Daemon 0.5.1
Monkey Monkey HTTP Daemon 0.6
Monkey Monkey HTTP Daemon 0.6.1
Solution:
The vendor has released version 0.6.2 to resolve this issue.
Gentoo has released an advisory for Gentoo Linux users. Gentoo users are advised to issue the following commands to update vulnerable systems:
emerge sync
emerge monkeyd
emerge clean
Monkey Monkey HTTP Daemon 0.4
-
Monkey Monkey HTTP Daemon 0.6.2
http://monkeyd.sourceforge.net/get_monkey.php?ver=4
Monkey Monkey HTTP Daemon 0.4.1
-
Monkey Monkey HTTP Daemon 0.6.2
http://monkeyd.sourceforge.net/get_monkey.php?ver=4
Monkey Monkey HTTP Daemon 0.4.2
-
Monkey Monkey HTTP Daemon 0.6.2
http://monkeyd.sourceforge.net/get_monkey.php?ver=4
Monkey Monkey HTTP Daemon 0.5
-
Monkey Monkey HTTP Daemon 0.6.2
http://monkeyd.sourceforge.net/get_monkey.php?ver=4
Monkey Monkey HTTP Daemon 0.5.1
-
Monkey Monkey HTTP Daemon 0.6.2
http://monkeyd.sourceforge.net/get_monkey.php?ver=4
Monkey Monkey HTTP Daemon 0.6
-
Monkey Monkey HTTP Daemon 0.6.2
http://monkeyd.sourceforge.net/get_monkey.php?ver=4
Monkey Monkey HTTP Daemon 0.6.1
-
Monkey Monkey HTTP Daemon 0.6.2
http://monkeyd.sourceforge.net/get_monkey.php?ver=4
References
Monkey HTTP Daemon Excessive POST Data Buffer Overflow Vulnerability
References:
References:
- Monkey HTTP Daemon Product Page (Monkey)
- Monkey HTTPd Remote Buffer Overflow (Matthew Murphy
)