PT-2017-4102 · Nginx+4 · Nginx+4

Publicado

2017-07-11

·

Atualizado

2026-04-21

·

CVE-2017-7529

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nginx versions 0.5.6 through 1.13.2 PAN-OS versions prior to 7.1.26 PAN-OS versions prior to 8.1.13 PAN-OS versions prior to 9.0.6 PAN-OS 8.0 (all versions)
Description The issue is caused by an integer overflow vulnerability in the nginx range filter module. This vulnerability can be exploited by a remote attacker using a specially crafted request, potentially leading to the leak of sensitive information. The vulnerability can also cause the leak of a cache file header if a response was returned from cache.
Recommendations For Nginx versions 0.5.6 through 1.13.2, update to version 1.21.0 or later. For PAN-OS versions prior to 7.1.26, update to version 7.1.26 or later. For PAN-OS versions prior to 8.1.13, update to version 8.1.13 or later. For PAN-OS versions prior to 9.0.6, update to version 9.0.6 or later. For PAN-OS 8.0, consider upgrading to a later version of PAN-OS that is not affected by this vulnerability.

Exploit

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1846
ALT-PU-2018-1866
BDU:2021-03045
CLEANSTART-2026-AF45008
CLEANSTART-2026-BA37192
CLEANSTART-2026-MQ02912
CLEANSTART-2026-XB16901
CLEANSTART-2026-ZN32454
CLEANSTART-2026-ZT77083
CVE-2017-7529
DLA-1024-1
DSA-3908-1
ELSA-2020-5859
ELSA-2020-5862
MGASA-2017-0231
OPENSUSE-SU-2018:0813-1
OPENSUSE-SU-2024:11092-1
OPENSUSE-SU-2024:11341-1
RHSA-2017:2538
SUSE-SU-2017:2387-1
USN-3352-1

Produtos afetados

Alt Linux
Apple Macos
Nginx
Pan-Os
Ubuntu