Описание
NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a specially crafted request. This may result in a denial of service (router process crash) or possibly have unspecified other impact.
Ссылки
- Release NotesVendor Advisory
- Mailing ListVendor Advisory
- Release NotesVendor Advisory
- Third Party AdvisoryVDB Entry
- Release NotesVendor Advisory
- Mailing ListVendor Advisory
- Release NotesVendor Advisory
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия от 0.3 (включая) до 1.7.1 (исключая)
cpe:2.3:a:f5:nginx_unit:*:*:*:*:*:*:*:*
EPSS
Процентиль: 86%
0.02977
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-787
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a specially crafted request. This may result in a denial of service (router process crash) or possibly have unspecified other impact.
CVSS3: 9.8
fstec
около 7 лет назад
Уязвимость сервера приложений Nginx Unit, вызванная переполнением буфера в динамической памяти, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
Процентиль: 86%
0.02977
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-787