PT-2014-1688 · Nginx+1 · Nginx+1
Publicado
2014-03-19
·
Atualizado
2024-06-15
·
CVE-2014-0133
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
nginx versions 1.3.15 through 1.4.7
nginx versions 1.5.x through 1.5.12
Description
The issue is related to a heap-based buffer overflow in the SPDY implementation, allowing remote attackers to execute arbitrary code via crafted requests.
Recommendations
For nginx versions 1.3.15 through 1.4.7, update to version 1.4.7 or later.
For nginx versions 1.5.x through 1.5.12, update to version 1.5.12 or later.
Correção
RCE
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Nginx