Lucene search

K
cveRedhatCVE-2012-2089
HistoryApr 17, 2012 - 9:55 p.m.

CVE-2012-2089

2012-04-1721:55:01
CWE-120
redhat
web.nvd.nist.gov
57
cve-2012-2089
buffer overflow
ngx_http_mp4_module
nginx
denial of service
memory overwrite
arbitrary code
remote attackers
nvd

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

High

EPSS

0.024

Percentile

90.0%

Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 through 1.0.14 and 1.1.3 through 1.1.18, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.

Affected configurations

Nvd
Node
f5nginxRange1.0.7–1.0.14
OR
f5nginxRange1.1.3–1.1.18
Node
fedoraprojectfedoraMatch15
OR
fedoraprojectfedoraMatch16
OR
fedoraprojectfedoraMatch17
VendorProductVersionCPE
f5nginx*cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
fedoraprojectfedora15cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:*
fedoraprojectfedora16cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:*
fedoraprojectfedora17cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

7.9

Confidence

High

EPSS

0.024

Percentile

90.0%