CVE-2013-2028
Publication date 20 July 2013
Last updated 24 July 2024
Ubuntu priority
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
Status
Package | Ubuntu Release | Status |
---|---|---|
nginx | ||
Notes
mdeslaur
upstream says "The problem affects nginx 1.3.9 - 1.4.0." code doesn't seem present in version 1.2.x in the archive
Patch details
Package | Patch details |
---|---|
nginx |