cbcvebase.
CVE-2009-2629
published 2009-09-15

CVE-2009-2629: Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote…

high7.5CVSS 3.1
AVNACLAuNCPIPAP
EXPLOIT
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiannginx< nginx 0.7.61-3 (bookworm)nginx 0.7.61-3 (bookworm)
f5nginx>= 0 < 0.7.61-30.7.61-3
f5nginx>= 0 < 0.7.61-30.7.61-3
f5nginx>= 0 < 0.7.61-30.7.61-3
f5nginx>= 0 < 0.7.61-30.7.61-3
f5nginx>= 0.1.0 < 0.5.380.5.38
f5nginx>= 0.6.0 < 0.6.390.6.39
f5nginx>= 0.7.0 < 0.7.620.7.62
f5nginx>= 0.8.0 < 0.8.150.8.15
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora

CVSS provenance

nvd7.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH