Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-68mc-8233-5xrw

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.

EPSS

Процентиль: 100%
0.92837
Критический

Дефекты

CWE-787

Связанные уязвимости

ubuntu
больше 12 лет назад

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.

nvd
больше 12 лет назад

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.

debian
больше 12 лет назад

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx ...

EPSS

Процентиль: 100%
0.92837
Критический

Дефекты

CWE-787