CVE-2013-2070
published 2013-07-20CVE-2013-2070: http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote…
PriorityP431medium5.8CVSS 2.0
AVNACMAuNCPINAP
EPSS
11.92%
95.7th percentile
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nginx | < nginx 1.4.1-1 (bookworm) | nginx 1.4.1-1 (bookworm) |
| f5 | nginx | >= 0 < 1.4.1-1 | 1.4.1-1 |
| f5 | nginx | >= 0 < 1.4.1-1 | 1.4.1-1 |
| f5 | nginx | >= 0 < 1.4.1-1 | 1.4.1-1 |
| f5 | nginx | >= 0 < 1.4.1-1 | 1.4.1-1 |
| f5 | nginx | 1.1.4 – 1.2.8 | — |
| f5 | nginx | 1.3.9 – 1.4.0 | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wwq6-8qmj-449j: http/modules/ngx_http_proxy_module
ghsa_unreviewed·2022-05-13·CVSS 7.5
CVE-2013-2070 [HIGH] GHSA-wwq6-8qmj-449j: http/modules/ngx_http_proxy_module
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
OSV
CVE-2013-2070: http/modules/ngx_http_proxy_module
osv·2013-07-20·CVSS 7.5
CVE-2013-2070 [HIGH] CVE-2013-2070: http/modules/ngx_http_proxy_module
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
Debian
CVE-2013-2070: nginx - http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 thro...
vendor_debian·2013·CVSS 7.5
CVE-2013-2070 [HIGH] CVE-2013-2070: nginx - http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 thro...
http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
Scope: local
bookworm: resolved (fixed in 1.4.1-1)
bullseye: resolved (fixed in 1.4.1-1)
forky: resolved (fixed in 1.4.1-1)
sid: resolved (fixed in 1.4.1-1)
trixie: resolved (fixed in 1.4.1-1)
No detection rules found.
Bugzilla
CVE-2013-2070 nginx: denial of service or memory disclosure when using proxy_pass
bugzilla·2013-05-13·CVSS 7.5
CVE-2013-2070 [HIGH] CVE-2013-2070 nginx: denial of service or memory disclosure when using proxy_pass
CVE-2013-2070 nginx: denial of service or memory disclosure when using proxy_pass
A similar security issue to CVE-2013-2028 was identified [1] for versions of nginx if proxy_pass to untrusted upstream HTTP servers are used, which could lead to a denial of service or a disclosure of a worker process' memory.
The problem affects nginx 1.1.4 - 1.2.8, 1.3.0 - 1.4.0 and was assigned the name CVE-2013-2070, so only Fedora 18 is affected.
http://nginx.org/download/patch.2013.proxy.txt
[1] http://www.openwall.com/lists/oss-security/2013/05/13/3
Discussion:
Created nginx tracking bugs for this issue
Affects: fedora-18 [bug 962526]
---
nginx-announce ML post:
http://mailman.nginx.org/pipermail/nginx-announce/2013/000114.html
---
nginx-1.2.9-1.fc18 has been pushed to the Fedora 18 stable r
Bugzilla
CVE-2013-2070 nginx: denial of service or memory disclosure when using proxy_pass [fedora-18]
bugzilla·2013-05-13·CVSS 5.8
CVE-2013-2070 [MEDIUM] CVE-2013-2070 nginx: denial of service or memory disclosure when using proxy_pass [fedora-18]
CVE-2013-2070 nginx: denial of service or memory disclosure when using proxy_pass [fedora-18]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-18 t
arXiv
The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization
arxiv_fulltext·2021-08-10
The Endokernel: Fast, Secure, and Programmable Subprocess Virtualization
-5em
## Abstract
Commodity applications contain more and more combinations of interacting
components (user, application, library, and system) and exhibit increasingly
diverse tradeoffs between isolation, performance, and programmability.
We argue that the challenge of future runtime isolation is best met by
embracing the multi-principle nature of applications, rethinking process
architecture for fast and extensible intra-process isolation.
We present, the , a new process model and security architecture that
nests an extensible monitor into the standard process for building efficient
least-authority abstractions.
The introduces a new virtual machine abstraction for representing
subprocess authority, which is enforced by an efficient self-isolating monitor
that maps the abstraction to s
http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105950.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2013/000114.htmlhttp://nginx.org/download/patch.2013.proxy.txthttp://seclists.org/oss-sec/2013/q2/291http://secunia.com/advisories/55181http://security.gentoo.org/glsa/glsa-201310-04.xmlhttp://www.debian.org/security/2013/dsa-2721http://www.openwall.com/lists/oss-security/2013/05/13/3http://www.securityfocus.com/bid/59824https://bugzilla.redhat.com/show_bug.cgi?id=962525https://exchange.xforce.ibmcloud.com/vulnerabilities/84172http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105950.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2013/000114.htmlhttp://nginx.org/download/patch.2013.proxy.txthttp://seclists.org/oss-sec/2013/q2/291http://secunia.com/advisories/55181http://security.gentoo.org/glsa/glsa-201310-04.xmlhttp://www.debian.org/security/2013/dsa-2721http://www.openwall.com/lists/oss-security/2013/05/13/3http://www.securityfocus.com/bid/59824https://bugzilla.redhat.com/show_bug.cgi?id=962525https://exchange.xforce.ibmcloud.com/vulnerabilities/84172
2013-07-20
Published