6.8
CVSSv2

CVE-2012-2089

Published: 17/04/2012 Updated: 10/11/2021
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in ngx_http_mp4_module.c in the ngx_http_mp4_module module in nginx 1.0.7 up to and including 1.0.14 and 1.1.3 up to and including 1.1.18, when the mp4 directive is used, allows remote malicious users to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

f5 nginx

fedoraproject fedora 15

fedoraproject fedora 16

fedoraproject fedora 17

Vendor Advisories

Buffer overflow in ngx_http_mp4_modulec in the ngx_http_mp4_module module in nginx 107 through 1014 and 113 through 1118, when the mp4 directive is used, allows remote attackers to cause a denial of service (memory overwrite) or possibly execute arbitrary code via a crafted MP4 file ...