Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-4450

Опубликовано: 07 июн. 2016
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5
CVSS3: 7.5

Описание

os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.

РелизСтатусПримечание
devel

released

1.10.1-0ubuntu1
esm-infra-legacy/trusty

released

1.4.6-1ubuntu3.5
esm-infra/xenial

released

1.10.0-0ubuntu0.16.04.2
precise

ignored

end of life
precise/esm

DNE

precise was needed
trusty

released

1.4.6-1ubuntu3.5
trusty/esm

released

1.4.6-1ubuntu3.5
upstream

released

1.10.1,1.11.1
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

EPSS

Процентиль: 88%
0.04016
Низкий

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

redhat
больше 9 лет назад

os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.

CVSS3: 7.5
nvd
больше 9 лет назад

os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.

CVSS3: 7.5
debian
больше 9 лет назад

os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 al ...

CVSS3: 7.5
github
больше 3 лет назад

os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.

CVSS3: 7.5
fstec
больше 9 лет назад

Уязвимость компонента os/unix/ngx_files.c платформы мониторинга и управления приложениями NGINX, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 88%
0.04016
Низкий

5 Medium

CVSS2

7.5 High

CVSS3