CVE-2016-4450
published 2016-06-07CVE-2016-4450: os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
16.38%
96.6th percentile
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | nginx | < nginx 1.10.1-1 (bookworm) | nginx 1.10.1-1 (bookworm) |
| f5 | nginx | — | — |
| f5 | nginx | >= 0 < 1.10.1-1 | 1.10.1-1 |
| f5 | nginx | >= 0 < 1.10.1-1 | 1.10.1-1 |
| f5 | nginx | >= 0 < 1.10.1-1 | 1.10.1-1 |
| f5 | nginx | >= 0 < 1.10.1-1 | 1.10.1-1 |
| f5 | nginx | >= 1.3.9 < 1.10.1 | 1.10.1 |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qw3j-mxg7-jx9v: os/unix/ngx_files
ghsa_unreviewed·2022-05-13
CVE-2016-4450 [HIGH] CWE-476 GHSA-qw3j-mxg7-jx9v: os/unix/ngx_files
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
OSV
CVE-2016-4450: os/unix/ngx_files
osv·2016-06-07·CVSS 7.5
CVE-2016-4450 [HIGH] CVE-2016-4450: os/unix/ngx_files
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
Palo Alto
PAN-SA-2020-0006 PAN-OS: Nginx software upgraded to resolve multiple vulnerabilities
vendor_paloalto·2020-05-13·CVSS 7.5
CVE-2016-4450 [HIGH] CWE-476 PAN-SA-2020-0006 PAN-OS: Nginx software upgraded to resolve multiple vulnerabilities
PAN-SA-2020-0006 PAN-OS: Nginx software upgraded to resolve multiple vulnerabilities
Nginx software included with PAN-OS has been upgraded to resolve multiple vulnerabilities. This issue affects: All PAN-OS 7.1 and 8.0 versions; PAN-OS 8.1 versions earlier than 8.1.14; PAN-OS 9.0 versions earlier than 9.0.7. The resolved vulnerabilities include: CVE CVSS Summary CVE-2016-4450 7.5 ( CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H ) os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file. CVE-2013-0337 7.5 AV:N/AC:L/Au:N/C:P/I:P/A:P The default configuration of nginx, possibly 1.3.13 and earlier,
Ubuntu
nginx vulnerability
vendor_ubuntu·2016-06-02
CVE-2016-4450 nginx vulnerability
Title: nginx vulnerability
Summary: nginx could be made to crash if it received specially crafted network
traffic.
It was discovered that nginx incorrectly handled saving client request
bodies to temporary files. A remote attacker could possibly use this issue
to cause nginx to crash, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nginx: NULL pointer dereference while writing client request body
vendor_redhat·2016-05-31·CVSS 7.5
CVE-2016-4450 [HIGH] CWE-476 nginx: NULL pointer dereference while writing client request body
nginx: NULL pointer dereference while writing client request body
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
A NULL pointer dereference flaw was found in the nginx code responsible for saving client request body to a temporary file. A remote attacker could send a specially crafted request that would cause nginx worker process to crash.
Package: nginx16-nginx (Red Hat Software Collections) - Will not fix
Debian
CVE-2016-4450: nginx - os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remot...
vendor_debian·2016·CVSS 7.5
CVE-2016-4450 [HIGH] CVE-2016-4450: nginx - os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remot...
os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
Scope: local
bookworm: resolved (fixed in 1.10.1-1)
bullseye: resolved (fixed in 1.10.1-1)
forky: resolved (fixed in 1.10.1-1)
sid: resolved (fixed in 1.10.1-1)
trixie: resolved (fixed in 1.10.1-1)
No detection rules found.
No public exploits indexed.
HackerOne
help.nextcloud.com: Known DoS condition (null pointer deref) in Nginx running
hackerone·2016-07-27·CVSS 7.5
CVE-2016-4450 [HIGH] help.nextcloud.com: Known DoS condition (null pointer deref) in Nginx running
help.nextcloud.com: Known DoS condition (null pointer deref) in Nginx running
The https://help.nextcloud.com sub-site is running Nginx/1.10.0 which is vuln to a known issue (CVE-2016-4450) which allows a remote malformed HTTP request to cause the Nginx process to crash.
DoS testing is mentioned as not requested, but if you know of an issue give it a go ..
You can determine the version running by requesting the IP of the site and getting the HTTP 301, eg: https://88.198.160.135
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-4450
Bugzilla
CVE-2016-4450 nginx: NULL pointer dereference while writing client request body
bugzilla·2016-06-01·CVSS 7.5
CVE-2016-4450 [HIGH] CVE-2016-4450 nginx: NULL pointer dereference while writing client request body
CVE-2016-4450 nginx: NULL pointer dereference while writing client request body
A vulnerability was found in nginx code responsible for saving
client request body to a temporary file. A specially crafted request
might result in worker process crash due to a NULL pointer dereference
while writing client request body to a temporary file.
External references:
http://mailman.nginx.org/pipermail/nginx-announce/2016/000179.html
Upstream patches:
[nginx 1.9.13 - 1.11.0]
http://nginx.org/download/patch.2016.write.txt
[nginx 1.3.9 - 1.9.12]
http://nginx.org/download/patch.2016.write2.txt
Discussion:
Created nginx tracking bugs for this issue:
Affects: fedora-all [bug 1341463]
Affects: epel-all [bug 1341464]
---
Upstream bug, https://trac.nginx.org/nginx/ticket/981
---
This issue has be
Bugzilla
CVE-2016-4450 nginx: NULL pointer dereference whilw writing client request body [epel-all]
bugzilla·2016-06-01·CVSS 7.5
CVE-2016-4450 [HIGH] CVE-2016-4450 nginx: NULL pointer dereference whilw writing client request body [epel-all]
CVE-2016-4450 nginx: NULL pointer dereference whilw writing client request body [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2016-4450 nginx: NULL pointer dereference whilw writing client request body [fedora-all]
bugzilla·2016-06-01·CVSS 7.5
CVE-2016-4450 [HIGH] CVE-2016-4450 nginx: NULL pointer dereference whilw writing client request body [fedora-all]
CVE-2016-4450 nginx: NULL pointer dereference whilw writing client request body [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
http://mailman.nginx.org/pipermail/nginx-announce/2016/000179.htmlhttp://www.debian.org/security/2016/dsa-3592http://www.securityfocus.com/bid/90967http://www.securitytracker.com/id/1036019http://www.ubuntu.com/usn/USN-2991-1https://access.redhat.com/errata/RHSA-2016:1425https://security.gentoo.org/glsa/201606-06http://mailman.nginx.org/pipermail/nginx-announce/2016/000179.htmlhttp://www.debian.org/security/2016/dsa-3592http://www.securityfocus.com/bid/90967http://www.securitytracker.com/id/1036019http://www.ubuntu.com/usn/USN-2991-1https://access.redhat.com/errata/RHSA-2016:1425https://security.gentoo.org/glsa/201606-06
2016-06-07
Published