The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial of service (crash) via an HTTP request with a sequence of "%" characters and a missing Host field.
| Software | From | Fixed in |
|---|---|---|
| monkey-project / monkey | 0.1.1 | 0.1.1.x |
| monkey-project / monkey | 0.5.2 | 0.5.2.x |
| monkey-project / monkey | 0.6.0 | 0.6.0.x |
| monkey-project / monkey | 0.6.1 | 0.6.1.x |
| monkey-project / monkey | 0.6.2 | 0.6.2.x |
| monkey-project / monkey | 0.6.3 | 0.6.3.x |
| monkey-project / monkey | 0.7.0 | 0.7.0.x |
| monkey-project / monkey | 0.7.1 | 0.7.1.x |
| monkey-project / monkey | 0.7.2 | 0.7.2.x |
| monkey-project / monkey | 0.8.0 | 0.8.0.x |
| monkey-project / monkey | - | 0.8.1.x |