CVE-2009-2629
published 2009-09-15CVE-2009-2629: Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote…
PriorityP269high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
75.08%
99.5th percentile
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nginx | < nginx 0.7.61-3 (bookworm) | nginx 0.7.61-3 (bookworm) |
| f5 | nginx | >= 0 < 0.7.61-3 | 0.7.61-3 |
| f5 | nginx | >= 0 < 0.7.61-3 | 0.7.61-3 |
| f5 | nginx | >= 0 < 0.7.61-3 | 0.7.61-3 |
| f5 | nginx | >= 0 < 0.7.61-3 | 0.7.61-3 |
| f5 | nginx | >= 0.1.0 < 0.5.38 | 0.5.38 |
| f5 | nginx | >= 0.6.0 < 0.6.39 | 0.6.39 |
| f5 | nginx | >= 0.7.0 < 0.7.62 | 0.7.62 |
| f5 | nginx | >= 0.8.0 < 0.8.15 | 0.8.15 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via a specially crafted URI containing a double-slash path traversal sequence (//../) sent in an HTTP GET request to nginx; monitor for HTTP requests with this URI pattern against nginx versions 0.1.0–0.5.37, 0.6.x < 0.6.39, 0.7.x < 0.7.62, 0.8.x < 0.8.15. ↗
- →The exploit payload embeds a bind-shell shellcode (port 31337) within the HTTP URI; detect outbound connections to port 31337 from the nginx worker process as a post-exploitation indicator. ↗
- ·The exploit targets 32-bit nginx builds; the null pointer and structure offsets in the PoC are 4-byte (32-bit) values and would need adjustment for 64-bit targets. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5MEDIUM
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nginx: ngx_http_parse_complex_uri() buffer underflow vulnerability (VU#180065)
vendor_redhat·2009-09-14·CVSS 7.5
CVE-2009-2629 [HIGH] nginx: ngx_http_parse_complex_uri() buffer underflow vulnerability (VU#180065)
nginx: ngx_http_parse_complex_uri() buffer underflow vulnerability (VU#180065)
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
Debian
CVE-2009-2629: nginx - Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6...
vendor_debian·2009·CVSS 7.5
CVE-2009-2629 [HIGH] CVE-2009-2629: nginx - Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6...
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
Scope: local
bookworm: resolved (fixed in 0.7.61-3)
bullseye: resolved (fixed in 0.7.61-3)
forky: resolved (fixed in 0.7.61-3)
sid: resolved (fixed in 0.7.61-3)
trixie: resolved (fixed in 0.7.61-3)
GHSA
GHSA-f36r-j88j-6j27: Buffer underflow in src/http/ngx_http_parse
ghsa_unreviewed·2022-05-02
CVE-2009-2629 [HIGH] CWE-787 GHSA-f36r-j88j-6j27: Buffer underflow in src/http/ngx_http_parse
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
OSV
CVE-2009-2629: Buffer underflow in src/http/ngx_http_parse
osv·2009-09-15·CVSS 7.5
CVE-2009-2629 [HIGH] CVE-2009-2629: Buffer underflow in src/http/ngx_http_parse
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
No detection rules found.
Bugzilla
CVE-2009-2629 nginx: ngx_http_parse_complex_uri() buffer underflow vulnerability (VU#180065)
bugzilla·2009-09-14·CVSS 7.5
CVE-2009-2629 [HIGH] CVE-2009-2629 nginx: ngx_http_parse_complex_uri() buffer underflow vulnerability (VU#180065)
CVE-2009-2629 nginx: ngx_http_parse_complex_uri() buffer underflow vulnerability (VU#180065)
Chris Ries at the Carnegie Mellon University Information Security Office discovered a flaw in nginx's ngx_http_parse_complex_uri() function used to parse URIs. Summary of the flaw from Chris:
A buffer underflow vulnerability exists in nginx that can be triggered by
a specially crafted URI. The vulnerability causes nginx to write bytes
from the URI to memory before the allocated buffer. The vulnerability
can be remotely exploited to crash the nginx worker process, or execute
arbitrary code in the context of the worker process. (which by default
appears to be run as 'nobody').
On Fedora, nginx non-privileged user is used instead.
CERT/CC is tracking this as VU#180065.
Upstream plans to release n
arXiv
Unlimited Lives: Secure In-Process Rollback with Isolated Domains
arxiv_fulltext·2023-04-21
Unlimited Lives: Secure In-Process Rollback with Isolated Domains
Unlimited Lives: Secure In-Process Rollback with Isolated Domains
Merve G\"ulmez
Ericsson Security Research
Kista, Sweden
imec-Distrinet, KU Leuven
Leuven, Belgium
merve.gulmez
@kuleuven.be
Thomas Nyman
Ericsson Product Security
Jorvas, Finland
thomas.nyman
@ericsson.com
Christoph Baumann
Ericsson Security Research
Kista, Sweden
christoph.baumann
@ericsson.com
Jan Tobias M\"uhlberg
imec-Distrinet, KU Leuven
Leuven, Belgium
Université Libre de Bruxelles
Brussels, Belgium
[email protected]
Unlimited Lives: Secure In-Process Rollback with Isolated
Domains
Merve Turhan
Ericsson Security Research
imec-DistriNet, KU Leuven
Thomas Nyman
Ericsson Product Security
Christoph Baumann
Ericsson Security Research
Jan Tobias M\"uhlberg
imec-DistriNet, KU Leuven
## Abstra
arXiv
The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization
arxiv_fulltext·2021-08-10
The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization
-5em
## Abstract
Commodity applications contain more and more combinations of interacting
components (user, application, library, and system) and exhibit increasingly
diverse tradeoffs between isolation, performance, and programmability.
We argue that the challenge of future runtime isolation is best met by
embracing the multi-principle nature of applications, rethinking process
architecture for fast and extensible intra-process isolation.
We present, the , a new process model and security architecture that
nests an extensible monitor into the standard process for building efficient
least-authority abstractions.
The introduces a new virtual machine abstraction for representing
subprocess authority, which is enforced by an efficient self-isolating monitor
that maps the abstraction to s
http://nginx.net/CHANGEShttp://nginx.net/CHANGES-0.5http://nginx.net/CHANGES-0.6http://nginx.net/CHANGES-0.7http://sysoev.ru/nginx/patch.180065.txthttp://www.debian.org/security/2009/dsa-1884http://www.kb.cert.org/vuls/id/180065https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.htmlhttp://nginx.net/CHANGEShttp://nginx.net/CHANGES-0.5http://nginx.net/CHANGES-0.6http://nginx.net/CHANGES-0.7http://sysoev.ru/nginx/patch.180065.txthttp://www.debian.org/security/2009/dsa-1884http://www.kb.cert.org/vuls/id/180065https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.htmlhttps://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html
2009-09-15
Published