CVE-2014-0088
published 2014-04-29CVE-2014-0088: The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute…
PriorityP352high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
8.66%
94.6th percentile
The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nginx | — | — |
| f5 | nginx | — | — |
| f5 | nginx | >= 0 < 1.4.6-1ubuntu3 | 1.4.6-1ubuntu3 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5w47-hrcw-f886: The SPDY implementation in the ngx_http_spdy_module module in nginx 1
ghsa_unreviewed·2022-05-13
CVE-2014-0088 [HIGH] CWE-119 GHSA-5w47-hrcw-f886: The SPDY implementation in the ngx_http_spdy_module module in nginx 1
The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.
OSV
CVE-2014-0088: The SPDY implementation in the ngx_http_spdy_module module in nginx 1
osv·2014-04-29·CVSS 7.5
CVE-2014-0088 [HIGH] CVE-2014-0088: The SPDY implementation in the ngx_http_spdy_module module in nginx 1
The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.
Red Hat
nginx: possible arbitrary code execution via SPDY implementation in 1.5.10
vendor_redhat·2014-03-04·CVSS 7.5
CVE-2014-0088 [HIGH] nginx: possible arbitrary code execution via SPDY implementation in 1.5.10
nginx: possible arbitrary code execution via SPDY implementation in 1.5.10
The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.
Package: nginx14-nginx (Red Hat Software Collections) - Not affected
Debian
CVE-2014-0088: nginx - The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 befor...
vendor_debian·2014·CVSS 7.5
CVE-2014-0088 [HIGH] CVE-2014-0088: nginx - The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 befor...
The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
HackerOne
SPDY memory corruption
hackerone·2014-03-24·CVSS 7.5
CVE-2014-0088 [HIGH] SPDY memory corruption
SPDY memory corruption
A bug in the experimental SPDY implementation in nginx 1.5.10 was found, which might allow an attacker to corrupt worker process memory by using a specially crafted request, potentially resulting in arbitrary code execution (CVE-2014-0088).
The problem only affects nginx 1.5.10 on 32-bit platforms, compiled with the ngx_http_spdy_module module (which is not compiled by default), if the "spdy" option of the "listen" directive is used in a configuration file.
The problem is fixed in nginx 1.5.11.
Patch for the problem can be found here:
http://nginx.org/download/patch.2014.spdy.txt
Thanks to Lucas Molas, researcher at Programa STIC, Fundación Dr. Manuel Sadosky, Buenos Aires, Argentina.
Bugzilla
CVE-2014-0088 nginx: possible arbitrary code execution via SPDY implementation in 1.5.10
bugzilla·2014-03-04·CVSS 7.5
CVE-2014-0088 [HIGH] CVE-2014-0088 nginx: possible arbitrary code execution via SPDY implementation in 1.5.10
CVE-2014-0088 nginx: possible arbitrary code execution via SPDY implementation in 1.5.10
The following security flaw in nginx was reported [1]:
A bug in the experimental SPDY implementation in nginx 1.5.10 was found, which might allow an attacker to corrupt worker process memory by using a specially crafted request, potentially resulting in arbitrary code execution (CVE-2014-0088).
The problem only affects nginx 1.5.10 on 32-bit platforms, compiled with the ngx_http_spdy_module module (which is not compiled by default), if the "spdy" option of the "listen" directive is used in a configuration file.
No Red Hat products, including Fedora and EPEL, ship this vulnerable version of nginx.
[1] http://mailman.nginx.org/pipermail/nginx-announce/2014/000132.html
2014-04-29
Published