Описание
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия от 0.7.52 (включая) до 0.7.67 (исключая)Версия от 0.8.0 (включая) до 0.8.40 (включая)
Одно из
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
EPSS
Процентиль: 91%
0.07504
Низкий
5 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
ubuntu
больше 15 лет назад
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
debian
больше 15 лет назад
nginx 0.8.36 allows remote attackers to cause a denial of service (cra ...
github
больше 3 лет назад
nginx 0.8.36 allows remote attackers to cause a denial of service (crash) via certain encoded directory traversal sequences that trigger memory corruption, as demonstrated using the "%c0.%c0." sequence.
EPSS
Процентиль: 91%
0.07504
Низкий
5 Medium
CVSS2
Дефекты
CWE-22