CVE-2013-2028
published 2013-07-20CVE-2013-2028: The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and…
PriorityP271high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
87.48%
99.7th percentile
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nginx | < nginx 1.4.1-1 (bookworm) | nginx 1.4.1-1 (bookworm) |
| debian | nginx | — | — |
| f5 | nginx | >= 0 < 1.4.1-1 | 1.4.1-1 |
| f5 | nginx | >= 0 < 1.4.1-1 | 1.4.1-1 |
| f5 | nginx | >= 0 < 1.4.1-1 | 1.4.1-1 |
| f5 | nginx | >= 0 < 1.4.1-1 | 1.4.1-1 |
| f5 | nginx | 1.1.4 – 1.2.8 | — |
| f5 | nginx | 1.3.9 – 1.4.0 | — |
| fedoraproject | fedora | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2013-2028 is a stack-based buffer overflow in nginx's chunked transfer encoding decoder that can be exploited to write to arbitrary memory locations, enabling ROP chain execution. ↗
- →CVE-2013-2028 is related to CVE-2013-2070, which involves crafted proxy responses to nginx 1.1.4–1.2.8 and 1.3.0–1.4.0 causing crashes and worker process memory disclosure via ngx_http_proxy_module.c. ↗
- ·CVE-2013-2070 (related to CVE-2013-2028) only manifests when nginx is configured with proxy_pass pointing to untrusted HTTP servers; deployments without proxy_pass are not affected by that specific variant. ↗
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2013-2028: nginx - The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 thro...
vendor_debian·2013·CVSS 7.5
CVE-2013-2028 [HIGH] CVE-2013-2028: nginx - The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 thro...
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2013-2070: nginx - http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 thro...
vendor_debian·2013·CVSS 7.5
CVE-2013-2070 [HIGH] CVE-2013-2070: nginx - http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 thro...
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
Scope: local
bookworm: resolved (fixed in 1.4.1-1)
bullseye: resolved (fixed in 1.4.1-1)
forky: resolved (fixed in 1.4.1-1)
sid: resolved (fixed in 1.4.1-1)
trixie: resolved (fixed in 1.4.1-1)
GHSA
GHSA-68mc-8233-5xrw: The ngx_http_parse_chunked function in http/ngx_http_parse
ghsa_unreviewed·2022-05-13
CVE-2013-2028 [HIGH] CWE-787 GHSA-68mc-8233-5xrw: The ngx_http_parse_chunked function in http/ngx_http_parse
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
GHSA
GHSA-wwq6-8qmj-449j: http/modules/ngx_http_proxy_module
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2013-2070 [HIGH] GHSA-wwq6-8qmj-449j: http/modules/ngx_http_proxy_module
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
OSV
CVE-2013-2070: http/modules/ngx_http_proxy_module
osv·2013-07-20·CVSS 7.5
CVE-2013-2070 [HIGH] CVE-2013-2070: http/modules/ngx_http_proxy_module
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
No detection rules found.
Exploit-DB
Nginx 1.4.0 (Generic Linux x64) - Remote Overflow
exploitdb·2014-03-15·CVSS 7.5
CVE-2013-2028 [HIGH] Nginx 1.4.0 (Generic Linux x64) - Remote Overflow
Nginx 1.4.0 (Generic Linux x64) - Remote Overflow
---
nginx <= 1.4.0 exploit for CVE-2013-2028
by sorbo
Fri Jul 12 14:52:45 PDT 2013
./brop.rb 127.0.0.1
for remote hosts:
./frag.sh ip
./brop.rb ip
rm state.bin when changing host (or relaunching nginx with canaries)
scan.py will find servers, reading IPs from ips.txt
This is a generic exploit for 64-bit nginx which uses a new attack technique (BROP) that does not rely on a particular target binary. It will work on any distro and even compiled from source installations.
Exploit-DB Mirror: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/32277.tgz
Exploit-DB
Nginx 1.3.9/1.4.0 (x86) - Brute Force
exploitdb·2013-07-11
CVE-2013-2028 Nginx 1.3.9/1.4.0 (x86) - Brute Force
Nginx 1.3.9/1.4.0 (x86) - Brute Force
---
#nginx 1.3.9/1.4.0 x86 brute force remote exploit
# copyright (c) 2013 kingcope
#----------------------------
#fix for internet exploitation, set MTU:
#ifconfig mtu 60000 up
#
###
# !!! WARNING !!!
# this exploit is unlikely to succeed when used against remote internet hosts.
# the reason is that nginx uses a non-blocking read() at the remote connection,
# this makes exploitation of targets on the internet highly unreliable.
# (it has been tested against a testbed on the internet but I couldn't exploit
# any other box with it. required was the above ifconfig setting on the client.
# maybe enabling large tcp frame support on a gigabit connection is more
# useful)
# so use it inside intranets only (duh!), this remains a PoC for now :D
# The exploit
Exploit-DB
Nginx 1.3.9 < 1.4.0 - Chuncked Encoding Stack Buffer Overflow (Metasploit)
exploitdb·2013-05-28
CVE-2013-2028 Nginx 1.3.9 < 1.4.0 - Chuncked Encoding Stack Buffer Overflow (Metasploit)
Nginx 1.3.9 'Nginx HTTP Server 1.3.9-1.4.0 Chuncked Encoding Stack Buffer Overflow',
'Description' => %q{
This module exploits a stack buffer overflow in versions 1.3.9 to 1.4.0 of nginx.
The exploit first triggers an integer overflow in the ngx_http_parse_chunked() by
supplying an overly long hex value as chunked block size. This value is later used
when determining the number of bytes to read into a stack buffer, thus the overflow
becomes possible.
},
'Author' =>
[
'Greg MacManus', # original discovery
'hal', # Metasploit module
'saelo' # Metasploit module
],
'DisclosureDate' => 'May 07 2013',
'License' => MSF_LICENSE,
'References' =>
[
['CVE', '2013-2028'],
['OSVDB', '93037'],
['URL', 'http://nginx.org/en/security_advisories.html'],
['URL', 'http://packetstormsecurity.com/files/121560/N
Exploit-DB
Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)
exploitdb·2013-05-17·CVSS 7.5
CVE-2013-2028 [HIGH] Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)
Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)
---
# Exploit Title: nginx v1.3.9-1.4.0 DOS POC (CVE-2013-2028)
# Google Dork: CVE-2013-2028
# Date: 16.05.2013
# Exploit Author: Mert SARICA - mert [ . ] sarica [ @ ] gmail [ . ] com - http://www.mertsarica.com
# Vendor Homepage: http://nginx.org/
# Software Link: http://nginx.org/download/nginx-1.4.0.tar.gz
# Version: 1.3.9-1.4.0
# Tested on: Kali Linux & nginx v1.4.0
# CVE : CVE-2013-2028
import httplib
import time
import socket
import sys
import os
# Vars & Defs
debug = 0
dos_packet = 0xFFFFFFFFFFFFFFEC
socket.setdefaulttimeout(1)
packet = 0
def chunk(data, chunk_size):
chunked = ""
chunked += "%s\r\n" % (chunk_size)
chunked += "%s\r\n" % (data)
chunked += "0\r\n\r\n"
return chunked
if sys.platform == 'linux-i386' or sys.platform ==
Metasploit
Nginx HTTP Server 1.3.9-1.4.0 Chunked Encoding Stack Buffer Overflow
metasploit
Nginx HTTP Server 1.3.9-1.4.0 Chunked Encoding Stack Buffer Overflow
Nginx HTTP Server 1.3.9-1.4.0 Chunked Encoding Stack Buffer Overflow
This module exploits a stack buffer overflow in versions 1.3.9 to 1.4.0 of nginx. The exploit first triggers an integer overflow in the ngx_http_parse_chunked() by supplying an overly long hex value as chunked block size. This value is later used when determining the number of bytes to read into a stack buffer, thus the overflow becomes possible.
arXiv
Retrofitting XoM for Stripped Binaries without Embedded Data Relocation
arxiv_fulltext·2025-10-06
Retrofitting XoM for Stripped Binaries without Embedded Data Relocation
Chenke Luo2,
Jiang Ming3,
Mengfei Xie2,
Guojun Peng2 and
Jianming Fu21
This paper has been accepted to Network and Distributed System Security (NDSS) Symposium 2025.
2Key Laboratory of Aerospace Information Security and Trusted Computing, Ministry of Education,
School of Cyber Science and Engineering, Wuhan University
3Department of Computer Science, School of Science and Engineering, Tulane University
Email: [email protected], [email protected], \mfxie96, guojpeng, jmfu\@whu.edu.cn
1 Jianming Fu is the corresponding author.
\@IEEEpubidpullup6.5
Network and Distributed System Security (NDSS) Symposium 2025
24-28 February 2025, San Diego, CA, USA
ISBN 979-8-9894372-8-3
https://dx.doi.org/10.14722/ndss.2025.240825
www.ndss-symposium.org
[ ]
plain
## Abstract
System progra
arXiv
NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA
arxiv_fulltext·2025-06-08
NanoZone: Scalable, Efficient, and Secure Memory Protection for Arm CCA
: Scalable, Efficient, and Secure Memory Protection for Arm CCA
@IEEEauthorhalign
@IEEEauthorhalign
Shiqi Liu12,
Yongpeng Gao1,
Mingyang Zhang1,
Jie Wang1
The corresponding author.
1Huazhong University of Science and Technology
2George Mason University
[email protected], \sternen_hust, zoneshiyi, wangjie_s\@hust.edu.cn
1 The full name of the affiliation is Hubei Key Laboratory of Distributed System Security, Hubei Engineering Research Center on Big Data Security, School of Cyber Science and Engineering, Huazhong University of Science and Technology.
## Abstract
Arm Confidential Computing Architecture (CCA) currently isolates at the granularity of an entire Confidential Virtual Machine (CVM), leaving intra-VM bugs such as Heartbleed unmitigated. The state-of-the-art narrows this to the p
arXiv
SYSPART: Automated Temporal System Call Filtering for Binaries
arxiv_fulltext·2023-09-27
SYSPART: Automated Temporal System Call Filtering for Binaries
ABSTRACT
: Automated Temporal System Call Filtering for Binaries
Vidya Lakshmi Rajagopalan
Stevens Institute of Technology
Hoboken, NJ
USA
Konstantinos Kleftogiorgos
Stevens Institute of Technology
Hoboken, NJ
USA
Enes G\"oktas
Stevens Institute of Technology
Hoboken, NJ
USA
Jun Xu
University of Utah
Salt Lake City,UT
USA
Georgios Portokalidis
Stevens Institute of Technology
Hoboken, NJ
USA
IMDEA Software Institute
Madrid
Spain
## Abstract
Restricting the system calls available to applications reduces the attack
surface of the kernel and limits the functionality available to compromised
applications. Recent approaches automatically identify the system calls
required by programs to block unneeded ones. For servers, they
even consider different phases of execution to tighten re
arXiv
CGuard: Efficient Spatial Safety for C
arxiv_fulltext·2023-08-29
CGuard: Efficient Spatial Safety for C
: Efficient Spatial Safety for C
printfolios=true
printacmref=false
plain
## Introduction
Spatial safety violations are the root cause of many security attacks . Attackers can exploit spatial safety bugs to hijack an application's control flow or steal sensitive information (e.g., passwords). Beyond security issues, spatial safety is
important
to ensure expected application behavior.
For example, unintentionally accessing an out-of-bounds location can cause unexpected behavior or program crashes that are hard to debug.
Spatial safety is just one aspect of reliability. Managed languages, such as Java and C#, offer better reliability by providing complete (spatial and temporal) memory and type safety. However, C does not guarantee any of these safeties by default. Despite the lack of me
arXiv
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
arxiv_fulltext·2022-09-26
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
Meghna Pancholi
[email protected]
Columbia University
Andreas D. Kellas
[email protected]
Columbia University
Vasileios P. Kemerlis
[email protected]
Brown University
Simha Sethumadhavan
[email protected]
Columbia University
## Abstract
We introduce , a novel technique for automatically learning system
call filtering policies for containerized microservices applications. At
run-time, automatically learns which system calls a program should
be allowed to invoke, while rejecting attempts to call spurious system calls.
Further, addresses many of the shortcomings of state-of-the-art
static analysis-based techniques, such as the ability to generate tight filters
for programs written in interpreted languages such as PHP, Python, and
JavaScript. has a simple and rob
arXiv
On-the-fly Code Activation for Attack Surface Reduction
arxiv_fulltext·2021-10-18
On-the-fly Code Activation for Attack Surface Reduction
On-the-fly Code Activation for Attack Surface Reduction
Chao Chen
[email protected]
Both authors contributed equally to the paper
Georgia Institute of Technology
Atlanta
GA
30332
Chris Porter
[email protected]
[1]
Georgia Institute of Technology
Atlanta
GA
30332
Santosh Pande
[email protected]
Georgia Institute of Technology
Atlanta
GA
30332
Chris Porter
Georgia Institute of Technology
Atlanta, USA
[email protected]
Sharjeel Khan
Georgia Institute of Technology
Atlanta, USA
[email protected]
Girish Mururu
Google
Atlanta, USA
[email protected]
Santosh Pande
Georgia Institute of Technology
Atlanta, USA
[email protected]
Chris Porter
Georgia Institute of Technology
Sharjeel Khan
Georgia Institute of Technology
Santosh Pande
Georgia Institute
arXiv
The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization
arxiv_fulltext·2021-08-10
The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization
-5em
## Abstract
Commodity applications contain more and more combinations of interacting
components (user, application, library, and system) and exhibit increasingly
diverse tradeoffs between isolation, performance, and programmability.
We argue that the challenge of future runtime isolation is best met by
embracing the multi-principle nature of applications, rethinking process
architecture for fast and extensible intra-process isolation.
We present, the , a new process model and security architecture that
nests an extensible monitor into the standard process for building efficient
least-authority abstractions.
The introduces a new virtual machine abstraction for representing
subprocess authority, which is enforced by an efficient self-isolating monitor
that maps the abstraction to s
arXiv
Intel MPX Explained: An Empirical Study of Intel MPX and Software-based Bounds Checking Approaches
arxiv_fulltext·2017-06-16
Intel MPX Explained: An Empirical Study of Intel MPX and Software-based Bounds Checking Approaches
Intel MPX Explained
An Empirical Study of Intel MPX and Software-based Bounds Checking Approaches
https://Intel-MPX.github.io
Oleksii Oleksenko^ , Dmitrii Kuvaiskii^
Pramod Bhatotia^*, Pascal Felber^ , and Christof Fetzer^
^ TU Dresden 5mm ^*The University of Edinburgh 5mm ^ University of Neuch\^atel
### Abstract
Memory-safety violations are a prevalent cause of both reliability and security vulnerabilities in systems software written in unsafe languages like C/C++.
Unfortunately, all the existing software-based solutions to this problem exhibit high performance overheads preventing them from wide adoption in production runs.
To address this issue, Intel recently released a new ISA extension---Memory Protection Extensions (), a hardware-assisted full-stack solution to protect against
arXiv
Bunshin: Compositing Security Mechanisms through Diversification (with Appendix)
arxiv_fulltext·2017-05-30
Bunshin: Compositing Security Mechanisms through Diversification (with Appendix)
: Compositing Security Mechanisms through Diversification
(with Appendix)
fancyplain
Rev.
\ of LastPage
Meng Xu,\;
Kangjie Lu,\;
Taesoo Kim,\;
Wenke Lee\;
Georgia Institute of Technology
## Abstract
A number of security mechanisms have been proposed
to harden programs written in unsafe languages, each of which
mitigates a specific type of memory error. Intuitively, enforcing
multiple security mechanisms on a target program will improve its
overall security. However,
this is not yet a viable approach in practice because the execution
slowdown caused by various security mechanisms is often
non-linearly accumulated, making the combined protection
prohibitively expensive; further, most security mechanisms are
designed for independent or isolated uses and thus are often in
conflict with
Bugzilla
CVE-2013-2070 nginx: denial of service or memory disclosure when using proxy_pass
bugzilla·2013-05-13·CVSS 7.5
CVE-2013-2070 [HIGH] CVE-2013-2070 nginx: denial of service or memory disclosure when using proxy_pass
CVE-2013-2070 nginx: denial of service or memory disclosure when using proxy_pass
A similar security issue to CVE-2013-2028 was identified [1] for versions of nginx if proxy_pass to untrusted upstream HTTP servers are used, which could lead to a denial of service or a disclosure of a worker process' memory.
The problem affects nginx 1.1.4 - 1.2.8, 1.3.0 - 1.4.0 and was assigned the name CVE-2013-2070, so only Fedora 18 is affected.
http://nginx.org/download/patch.2013.proxy.txt
[1] http://www.openwall.com/lists/oss-security/2013/05/13/3
Discussion:
Created nginx tracking bugs for this issue
Affects: fedora-18 [bug 962526]
---
nginx-announce ML post:
http://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html
---
nginx-1.2.9-1.fc18 has been pushed to the Fedora 18 stable r
Bugzilla
CVE-2013-2028 nginx: Stack-based buffer overflow when handling certain chunked transfer encoding requests [fedora-rawhide]
bugzilla·2013-05-07·CVSS 7.5
CVE-2013-2028 [HIGH] CVE-2013-2028 nginx: Stack-based buffer overflow when handling certain chunked transfer encoding requests [fedora-rawhide]
CVE-2013-2028 nginx: Stack-based buffer overflow when handling certain chunked transfer encoding requests [fedora-rawhide]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field
Bugzilla
CVE-2013-2028 nginx: Stack-based buffer overflow when handling certain chunked transfer encoding requests
bugzilla·2013-05-07·CVSS 7.5
CVE-2013-2028 [HIGH] CVE-2013-2028 nginx: Stack-based buffer overflow when handling certain chunked transfer encoding requests
CVE-2013-2028 nginx: Stack-based buffer overflow when handling certain chunked transfer encoding requests
A stack-based buffer overflow flaw was found in the way Nginx, a high performance web server and reverse proxy server for HTTP, SMTP, POP3, and IMAP protocols, performed processing of certain chunked transfer encoding HTTP requests. A remote attacker could provide a HTTP request with specially-crafted size or length values of the chunked packet that, when processed would lead to nginx daemon / service crash.
References:
[1] http://www.openwall.com/lists/oss-security/2013/05/07/3
Relevant upstream patch:
[2] http://nginx.org/download/patch.2013.chunked.txt
Discussion:
This issue did NOT affect the versions of the nginx package, as shipped with Fedora release of 17, 18, Fedora EPEL-
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105176.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2013/000112.htmlhttp://nginx.org/download/patch.2013.chunked.txthttp://packetstormsecurity.com/files/121675/Nginx-1.3.9-1.4.0-Denial-Of-Service.htmlhttp://secunia.com/advisories/55181http://security.gentoo.org/glsa/glsa-201310-04.xmlhttp://www.osvdb.org/93037http://www.securityfocus.com/bid/59699http://www.vnsecurity.net/2013/05/analysis-of-nginx-cve-2013-2028/https://github.com/rapid7/metasploit-framework/pull/1834http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105176.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2013/000112.htmlhttp://nginx.org/download/patch.2013.chunked.txthttp://packetstormsecurity.com/files/121675/Nginx-1.3.9-1.4.0-Denial-Of-Service.htmlhttp://secunia.com/advisories/55181http://security.gentoo.org/glsa/glsa-201310-04.xmlhttp://www.osvdb.org/93037http://www.securityfocus.com/bid/59699http://www.vnsecurity.net/2013/05/analysis-of-nginx-cve-2013-2028/https://github.com/rapid7/metasploit-framework/pull/1834
2013-07-20
Published