Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-21699
HistoryAug 22, 2023 - 12:00 a.m.

CVE-2020-21699

2023-08-2200:00:00
ubuntu.com
ubuntu.com
23
tengine
web server
integer overflow
vulnerability
nginx
range filter module
sensitive information
cve-2020-21699

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.963 High

EPSS

Percentile

99.5%

The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru
1.13.2 is vulnerable to an integer overflow vulnerability in the nginx
range filter module, resulting in the leakage of potentially sensitive
information triggered by specially crafted requests.

Notes

Author Note
mdeslaur This CVE only applies to the Tengine web server, which is a fork of nginx. The original nginx CVE was CVE-2017-7529.

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.963 High

EPSS

Percentile

99.5%