![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.152333 |
Category: | Web Servers |
Title: | Nginx 1.25.0 - 1.26.0 Multiple HTTP/3 Vulnerabilities |
Summary: | Nginx is prone to multiple HTTP/3 Vulnerabilities. |
Description: | Summary: Nginx is prone to multiple HTTP/3 Vulnerabilities. Vulnerability Insight: The following vulnerabilities exist: - CVE-2024-31079: Stack overflow and use-after-free in HTTP/3 - CVE-2024-32760: Buffer overwrite in HTTP/3 - CVE-2024-34161: Memory disclosure in HTTP/3 - CVE-2024-35200: NULL pointer dereference in HTTP/3 Affected Software/OS: Nginx versions 1.25.0 through 1.26.0. Solution: Update to version 1.26.1 or later. CVSS Score: 6.4 CVSS Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2024-31079 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/R7RPLWC35WHEUFCGKNFG62ESNID25TEZ/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MLAOKJWDALQZBIV3WKGPJ6T5Z56D3PRD/ https://my.f5.com/manage/s/article/K000139611 http://www.openwall.com/lists/oss-security/2024/05/30/4 Common Vulnerability Exposure (CVE) ID: CVE-2024-32760 https://my.f5.com/manage/s/article/K000139609 Common Vulnerability Exposure (CVE) ID: CVE-2024-34161 https://my.f5.com/manage/s/article/K000139627 Common Vulnerability Exposure (CVE) ID: CVE-2024-35200 https://my.f5.com/manage/s/article/K000139612 |
Copyright | Copyright (C) 2024 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |