Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-2028

Опубликовано: 20 июл. 2013
Источник: nvd
CVSS2: 7.5
EPSS Критический

Описание

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
Версия от 1.3.9 (включая) до 1.4.0 (включая)
Конфигурация 2
cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*

EPSS

Процентиль: 100%
0.92837
Критический

7.5 High

CVSS2

Дефекты

CWE-787

Связанные уязвимости

ubuntu
больше 12 лет назад

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.

debian
больше 12 лет назад

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx ...

github
больше 3 лет назад

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.

EPSS

Процентиль: 100%
0.92837
Критический

7.5 High

CVSS2

Дефекты

CWE-787