[NGINX:CVE-2013-2070] Memory disclosure with specially crafted HTTP backend responses

Severity Medium
Affected Packages 2
Unaffected Packages 3
CVEs 1

http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.

Package Affected Version
pkg:nginx/nginx >= 1.1.4, <= 1.2.8
pkg:nginx/nginx >= 1.3.9, <= 1.4.0
Package Unaffected Version
pkg:nginx/nginx >= 1.5.0
pkg:nginx/nginx >= 1.4.1
pkg:nginx/nginx >= 1.2.9
ID
NGINX:CVE-2013-2070
Severity
medium
Published
2013-07-20T03:37:25
(11 years ago)
Modified
2013-07-20T03:37:25
(11 years ago)
Rights
NGINX Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:nginx/nginx nginx >= 1.1.4 <= 1.2.8
Affected pkg:nginx/nginx nginx >= 1.3.9 <= 1.4.0
Unaffected pkg:nginx/nginx nginx >= 1.5.0
Unaffected pkg:nginx/nginx nginx >= 1.4.1
Unaffected pkg:nginx/nginx nginx >= 1.2.9
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...