MEDIUM
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028
Published Jul 18, 2013
5.8
MEDIUMCVSS 2.0
EPSS 11.92%
Description
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
Affected products
No data.
Configuration 2
OR
- 6.0
- 7.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (11)
- http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105950.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html mailing-listx_refsource_MLISTPatchVendor Advisory
- http://nginx.org/download/patch.2013.proxy.txt x_refsource_MISCPatchVendor Advisory
- http://seclists.org/oss-sec/2013/q2/291 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://secunia.com/advisories/55181 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://security.gentoo.org/glsa/glsa-201310-04.xml vendor-advisoryx_refsource_GENTOOThird Party Advisory
- http://www.debian.org/security/2013/dsa-2721 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.openwall.com/lists/oss-security/2013/05/13/3 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/59824 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=962525 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/84172 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105950.html | vendor-advisoryx_refsource_FEDORAThird Party Advisory | |
| http://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html | mailing-listx_refsource_MLISTPatchVendor Advisory | |
| http://nginx.org/download/patch.2013.proxy.txt | x_refsource_MISCPatchVendor Advisory | |
| http://seclists.org/oss-sec/2013/q2/291 | mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory | |
| http://secunia.com/advisories/55181 | third-party-advisoryx_refsource_SECUNIAThird Party Advisory | |
| http://security.gentoo.org/glsa/glsa-201310-04.xml | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| http://www.debian.org/security/2013/dsa-2721 | vendor-advisoryx_refsource_DEBIANThird Party Advisory | |
| http://www.openwall.com/lists/oss-security/2013/05/13/3 | mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory | |
| http://www.securityfocus.com/bid/59824 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://bugzilla.redhat.com/show_bug.cgi?id=962525 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/84172 | vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 18, 2013
Updated Aug 6, 2024
Reserved Feb 19, 2013
Link CVE-2013-2070
CISA Vulnrichment
Updated n/a