5.8
CVSSv2

CVE-2013-2070

Published: 20/07/2013 Updated: 10/11/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

http/modules/ngx_http_proxy_module.c in nginx 1.1.4 up to and including 1.2.8 and 1.3.0 up to and including 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote malicious users to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

f5 nginx

debian debian linux 6.0

debian debian linux 7.0

Vendor Advisories

Debian Bug report logs - #708164 nginx proxy_pass buffer overflow (CVE-2013-2070) Package: nginx; Maintainer for nginx is Debian Nginx Maintainers <pkg-nginx-maintainers@alioth-listsdebiannet>; Source for nginx is src:nginx (PTS, buildd, popcon) Reported by: Thijs Kinkhorst <thijs@debianorg> Date: Mon, 13 May 2013 ...
http/modules/ngx_http_proxy_modulec in nginx 114 through 128 and 130 through 140, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028 ...