Описание
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
A NULL pointer dereference flaw was found in the nginx code responsible for saving client request body to a temporary file. A remote attacker could send a specially crafted request that would cause nginx worker process to crash.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Software Collections | nginx16-nginx | Will not fix | ||
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-nginx18-nginx | Fixed | RHSA-2016:1425 | 14.07.2016 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | rh-nginx18-nginx | Fixed | RHSA-2016:1425 | 14.07.2016 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-nginx18-nginx | Fixed | RHSA-2016:1425 | 14.07.2016 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nginx18-nginx | Fixed | RHSA-2016:1425 | 14.07.2016 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUS | rh-nginx18-nginx | Fixed | RHSA-2016:1425 | 14.07.2016 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUS | rh-nginx18-nginx | Fixed | RHSA-2016:1425 | 14.07.2016 |
Показывать по
Дополнительная информация
Статус:
4.3 Medium
CVSS2
Связанные уязвимости
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 al ...
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
Уязвимость компонента os/unix/ngx_files.c платформы мониторинга и управления приложениями NGINX, позволяющая нарушителю вызвать отказ в обслуживании
4.3 Medium
CVSS2