PT-2012-3110 · Nginx · Nginx

Vincent Danen

·

Published

2012-04-17

·

Updated

2021-11-10

·

CVE-2012-1180

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions nginx versions prior to 1.0.14 nginx versions 1.1.x prior to 1.1.17
Description A use-after-free issue allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
Recommendations For versions prior to 1.0.14, update to version 1.0.14 or later. For versions 1.1.x prior to 1.1.17, update to version 1.1.17 or later.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-1180
DSA-2434-1

Affected Products

Nginx