Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.kb.cert.org/vuls/id/180065 | third party advisory us government resource |
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html | third party advisory vendor advisory |
http://nginx.net/CHANGES-0.7 | release notes vendor advisory |
http://nginx.net/CHANGES | release notes vendor advisory |
http://sysoev.ru/nginx/patch.180065.txt | broken link |
http://www.debian.org/security/2009/dsa-1884 | third party advisory vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html | third party advisory vendor advisory |
https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html | third party advisory vendor advisory |
http://nginx.net/CHANGES-0.5 | release notes vendor advisory |
http://nginx.net/CHANGES-0.6 | release notes vendor advisory |