Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-34161

Опубликовано: 29 мая 2024
Источник: debian
EPSS Низкий

Описание

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nginxfixed1.26.0-2package
nginxnot-affectedbookwormpackage
nginxnot-affectedbullseyepackage
nginxnot-affectedbusterpackage

Примечания

  • https://mailman.nginx.org/pipermail/nginx-announce/2024/GMY32CSHFH6VFTN76HJNX7WNEX4RLHF6.html

  • HTTP3 not enabled in Debian builds until 1.26.0-2 (which included fixes)

EPSS

Процентиль: 55%
0.00867
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.

CVSS3: 5.3
redhat
около 2 лет назад

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.

CVSS3: 5.3
nvd
около 2 лет назад

When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.

CVSS3: 5.3
fstec
около 2 лет назад

Уязвимость модуля HTTP/3 QUIC (ngx_http_v3_module) веб-серверов NGINX Plus и NGINX OSS, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 7.5
redos
около 2 лет назад

Множественные уязвимости nginx

EPSS

Процентиль: 55%
0.00867
Низкий