Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-2070
HistoryJul 20, 2013 - 12:00 a.m.

CVE-2013-2070

2013-07-2000:00:00
ubuntu.com
ubuntu.com
25

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.152

Percentile

95.9%

http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0
through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows
remote attackers to cause a denial of service (crash) and obtain sensitive
information from worker process memory via a crafted proxy response, a
similar vulnerability to CVE-2013-2028.

Bugs

Notes

Author Note
jdstrand per upstream 1.1.4 and higher
OSVersionArchitecturePackageVersionFilename
ubuntu12.04noarchnginx<ย 1.1.19-1ubuntu0.2UNKNOWN
ubuntu12.10noarchnginx<ย 1.2.1-2.2ubuntu0.1UNKNOWN
ubuntu13.04noarchnginx<ย 1.2.6-1ubuntu3.2UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.152

Percentile

95.9%