Skip to main content

nginx "ngx_http_parse_chunked()" Buffer Overflow Vulnerability

Last Update Date: 8 May 2013 10:41 Release Date: 8 May 2013 3644 Views

RISK: Medium Risk

TYPE: Servers - Web Servers

TYPE: Web Servers

A vulnerability has been identified in nginx, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is caused due to an error within the "ngx_http_parse_chunked()" function (http/ngx_http_parse.c) when parsing an HTTP chunk and can be exploited to cause a stack-based buffer overflow.


Impact

  • Remote Code Execution

System / Technologies affected

  • nginx 1.3.9 / 1.4.0

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Update to version 1.5.0 or 1.4.1

Vulnerability Identifier


Source


Related Link