Описание
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
A flaw within the processing of ranged HTTP requests has been discovered in the range filter module of nginx. A remote attacker could possibly exploit this flaw to disclose parts of the cache file header, or, if used in combination with third party modules, disclose potentially sensitive memory by sending specially crafted HTTP requests.
Отчет
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Software Collections | rh-nginx112-nginx | Not affected | ||
Red Hat Software Collections | rh-nginx18-nginx | Will not fix | ||
Red Hat Software Collections for Red Hat Enterprise Linux 6 | rh-nginx110-nginx | Fixed | RHSA-2017:2538 | 28.08.2017 |
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUS | rh-nginx110-nginx | Fixed | RHSA-2017:2538 | 28.08.2017 |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nginx110-nginx | Fixed | RHSA-2017:2538 | 28.08.2017 |
Red Hat Software Collections for Red Hat Enterprise Linux 7.3 EUS | rh-nginx110-nginx | Fixed | RHSA-2017:2538 | 28.08.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable t ...
EPSS
5.3 Medium
CVSS3