| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.100276 |
| Category: | Web Servers |
| Title: | nginx HTTP Request Remote Buffer Overflow Vulnerability |
| Summary: | Determine if nginx is prone to a buffer-overflow vulnerability |
| Description: | Overview: The 'nginx' program is prone to a buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data. Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition. Solution: Updates are available. Please see the references for more information. References: http://www.securityfocus.com/bid/36384 http://nginx.net/CHANGES-0.5 http://nginx.net/CHANGES-0.6 http://nginx.net/CHANGES-0.7 http://nginx.net/CHANGES http://nginx.net/ http://www.kb.cert.org/vuls/id/180065 |
| Cross-Ref: |
BugTraq ID: 36384 Common Vulnerability Exposure (CVE) ID: CVE-2009-2629 Debian Security Information: DSA-1884 (Google Search) http://www.debian.org/security/2009/dsa-1884 https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html CERT/CC vulnerability note: VU#180065 http://www.kb.cert.org/vuls/id/180065 |
| Copyright | This script is Copyright (C) 2009 Greenbone Networks GmbH |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|