Lucene search

K
nessusTenable6458.PRM
HistoryApr 17, 2012 - 12:00 a.m.

nginx < 1.0.15 / 1.1.x < 1.1.19 Buffer-Overflow Vulnerability

2012-04-1700:00:00
Tenable
www.tenable.com
12

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.024

Percentile

90.0%

The remote host is running a nginx HTTP server.

Versions earlier than 1.0.15(stable version) or versions earlier than 1.1.19(development version) are vulnerable to a buffer-overflow vulnerability because it fails to perform adequate checks on user-supplied input. An attacker can exploit this issue by using a specially-crafted mp4 file, allowing the attacker to execute arbitrary code in the context of the application. (CVE-2012-2089)

Binary data 6458.prm

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS

0.024

Percentile

90.0%