Nginx CVE-2017-7529 Remote Integer Overflow Vulnerability
by CIRT Team
Description: Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
Impact: Attackers can exploit this issue to obtain sensitive information or may crash the application resulting in a denial-of-service condition.
Mitigation: Updates are available. Please check specific vendor advisory for more information.
Reference URL’s:
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=2017-7529
- http://www.securityfocus.com/bid/99534/info
- http://nginx.org/en/security_advisories.html
- http://mailman.nginx.org/pipermail/nginx-announce/2017/000200.html
Recommended Posts
Active Exploitation of Critical F5 BIG – IP Vulnerability (CVE–2023-46747) Uncovered in Bangladesh
06 Nov 2024 - Security Advisories & Alerts