[FREEBSD:89DB3B31-A4C3-11E3-978F-F0DEF16C5C1B] nginx -- SPDY memory corruption
Severity
High
Affected Packages
1
CVEs
1
The nginx project reports:
A bug in the experimental SPDY implementation in nginx 1.5.10 was found,
which might allow an attacker to corrupt worker process memory by using
a specially crafted request, potentially resulting in arbitrary code
execution (CVE-2014-0088).
The problem only affects nginx 1.5.10 on 32-bit platforms, compiled with
the ngx_http_spdy_module module (which is not compiled by default), if
the "spdy" option of the "listen" directive is used in a configuration
file.
Package | Affected Version |
---|---|
pkg:freebsd/nginx-devel |
- ID
- FREEBSD:89DB3B31-A4C3-11E3-978F-F0DEF16C5C1B
- Severity
- high
- Severity from
- CVE-2014-0088
- URL
- http://vuxml.freebsd.org/freebsd/89db3b31-a4c3-11e3-978f-f0def16c5c1b.html
- Published
-
2014-03-04T00:00:00
(10 years ago) - Modified
-
2014-03-06T00:00:00
(10 years ago) - Rights
- FreeBSD VuXML Security Team
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
FreeBSD VuXML | http://mailman.nginx.org/pipermail/nginx-announce/2014/000132.html |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:freebsd/nginx-devel | nginx-devel |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |