VulnerabilityModified
CVE-2017-7529
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
HIGH 7.5EPSS 62.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 62.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 62.60% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- f5/nginx · puppet/puppet enterprise · apple/xcode
- Source
- secalert@redhat.com
References
- http://mailman.nginx.org/pipermail/nginx-announce/2017/000200.htmlVendor Advisory
- http://seclists.org/fulldisclosure/2021/Sep/36Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/99534Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039238Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2538Third Party Advisory
- https://puppet.com/security/cve/cve-2017-7529Third Party Advisory
- https://support.apple.com/kb/HT212818Third Party Advisory
- http://mailman.nginx.org/pipermail/nginx-announce/2017/000200.htmlVendor Advisory
- http://seclists.org/fulldisclosure/2021/Sep/36Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/99534Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039238Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:2538Third Party Advisory
- https://puppet.com/security/cve/cve-2017-7529Third Party Advisory
- https://support.apple.com/kb/HT212818Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.