CVE-2017-7529
published 2017-07-13CVE-2017-7529: Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of…
PriorityP259high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
62.60%
99.1th percentile
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 13.0 | 13.0 |
| apple | xcode | — | — |
| debian | nginx | < nginx 1.13.3-1 (bookworm) | nginx 1.13.3-1 (bookworm) |
| f5 | nginx | >= 0 < 1.13.3-1 | 1.13.3-1 |
| f5 | nginx | >= 0 < 1.13.3-1 | 1.13.3-1 |
| f5 | nginx | >= 0 < 1.13.3-1 | 1.13.3-1 |
| f5 | nginx | >= 0 < 1.13.3-1 | 1.13.3-1 |
| f5 | nginx | 0.5.6 – 1.12.1 | — |
| f5 | nginx | 1.13.0 – 1.13.2 | — |
| nginx | nginx | — | — |
| paloalto | pan-os | — | — |
| puppet | puppet_enterprise | < 2016.4.7 | 2016.4.7 |
| puppet | puppet_enterprise | 2017.1.0 – 2017.1.1 | — |
| puppet | puppet_enterprise | 2017.2.1 – 2017.2.3 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Attacks against CVE-2017-7529 can be blocked with Palo Alto Networks Unique Threat ID 33070 signature enabled on a firewall configured to protect vulnerable management interfaces. ↗
- →The vulnerability is triggered by a specially crafted HTTP Range request targeting the nginx range filter module; monitor for anomalous or malformed Range headers in HTTP requests to nginx servers. ↗
- →Nginx versions 0.5.6 through 1.13.2 (inclusive) are vulnerable; flag or alert on these version strings in server banners or package inventories. ↗
- ·Exploitation only leaks cache file header content when a response was served from cache; impact is limited if nginx caching is not enabled. ↗
- ·Memory disclosure beyond the cache file header requires the presence of third-party nginx modules; base nginx deployments have reduced exposure. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-85mj-h68w-w736: Nginx versions since 0
ghsa_unreviewed·2022-05-13
CVE-2017-7529 [HIGH] CWE-190 GHSA-85mj-h68w-w736: Nginx versions since 0
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
OSV
CVE-2017-7529: Nginx versions since 0
osv·2017-07-13·CVSS 7.5
CVE-2017-7529 [HIGH] CVE-2017-7529: Nginx versions since 0
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
Apple
CVE-2017-7529: Xcode 13
vendor_apple·2021-09-20·CVSS 7.5
CVE-2017-7529 [HIGH] CVE-2017-7529: Xcode 13
Apple Security Update: About the security content of Xcode 13
Product: Xcode
Version: 13
CVE: CVE-2017-7529
Component: CVE-2017-7529
Palo Alto
PAN-OS: Nginx integer overflow may lead to information leak
vendor_paloalto·2020-05-13·CVSS 7.5
CVE-2017-7529 [HIGH] CWE-190 PAN-OS: Nginx integer overflow may lead to information leak
PAN-OS: Nginx integer overflow may lead to information leak
Nginx web-server included with PAN-OS is vulnerable to an integer overflow vulnerability that can leak potentially a cache file header if a response was returned from cache.
This issue affects:
PAN-OS 7.1 versions earlier than 7.1.26;
PAN-OS 8.1 versions earlier than 8.1.13;
PAN-OS 9.0 versions earlier than 9.0.6;
All versions of PAN-OS 8.0.
Affected products: PAN-OS
Solution: This issue is fixed in PAN-OS 7.1.26, PAN-OS 8.1.13, PAN-OS 9.0.6, PAN-OS 9.1.0, and all later PAN-OS versions.
Workaround: Attacks against CVE-2017-7529 can be blocked with signatures for Unique Threat ID 33070 enabled on a different firewall configured to protect the vulnerable management interfaces.
Ubuntu
nginx vulnerability
vendor_ubuntu·2017-07-13
CVE-2017-7529 nginx vulnerability
Title: nginx vulnerability
Summary: nginx could be made to expose sensitive information over the network.
It was discovered that an integer overflow existed in the range filter
feature of nginx. A remote attacker could use this to expose
sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
nginx: Integer overflow in nginx range filter module leading to memory disclosure
vendor_redhat·2017-07-11·CVSS 7.5
CVE-2017-7529 [HIGH] CWE-190 nginx: Integer overflow in nginx range filter module leading to memory disclosure
nginx: Integer overflow in nginx range filter module leading to memory disclosure
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
A flaw within the processing of ranged HTTP requests has been discovered in the range filter module of nginx. A remote attacker could possibly exploit this flaw to disclose parts of the cache file header, or, if used in combination with third party modules, disclose potentially sensitive memory by sending specially crafted HTTP requests.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in fut
Debian
CVE-2017-7529: nginx - Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer ...
vendor_debian·2017·CVSS 7.5
CVE-2017-7529 [HIGH] CVE-2017-7529: nginx - Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer ...
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
Scope: local
bookworm: resolved (fixed in 1.13.3-1)
bullseye: resolved (fixed in 1.13.3-1)
forky: resolved (fixed in 1.13.3-1)
sid: resolved (fixed in 1.13.3-1)
trixie: resolved (fixed in 1.13.3-1)
No detection rules found.
No public exploits indexed.
HackerOne
https://publishers.basicattentiontoken.org/favicon.ico is Vulnerable to CVE-2017-7529
hackerone·2020-12-16·CVSS 7.5
CVE-2017-7529 [HIGH] https://publishers.basicattentiontoken.org/favicon.ico is Vulnerable to CVE-2017-7529
https://publishers.basicattentiontoken.org/favicon.ico is Vulnerable to CVE-2017-7529
ou can verify the vulnerability by executing attached POC.
python CVE_2017_7529.py https://publishers.basicattentiontoken.org/favicon.ico
command.
All details available at
https://nvd.nist.gov/vuln/detail/CVE-2017-7529
https://gist.github.com/thehappydinoa/bc3278aea845b4f578362e9363c51115
Please do the needful.
## Impact
The POC demonstrates working exploint.
In the exploit function the script 'determines' if the server is vulnerable based on the response. Specifically in determining if the vulnerability exists, the script sends a request with some calculated "Range" value, based on the response content. More specifically, it tries to get the byte range from 623 bytes after the full content until t
HackerOne
Integer Overflow (CVE_2017_7529)
hackerone·2020-07-13
[MEDIUM] Integer Overflow (CVE_2017_7529)
Integer Overflow (CVE_2017_7529)
Integer Overflow - The issue affects nginx 0.5.6 - 1.13.2.
Bugzilla
CVE-2017-7529 nginx: Integer overflow in nginx range filter module leading to memory disclosure [epel-all]
bugzilla·2017-07-12·CVSS 7.5
CVE-2017-7529 [HIGH] CVE-2017-7529 nginx: Integer overflow in nginx range filter module leading to memory disclosure [epel-all]
CVE-2017-7529 nginx: Integer overflow in nginx range filter module leading to memory disclosure [epel-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1468584
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that user
Bugzilla
CVE-2017-7529 nginx: Integer overflow in nginx range filter module leading to memory disclosure [fedora-all]
bugzilla·2017-07-12·CVSS 7.5
CVE-2017-7529 [HIGH] CVE-2017-7529 nginx: Integer overflow in nginx range filter module leading to memory disclosure [fedora-all]
CVE-2017-7529 nginx: Integer overflow in nginx range filter module leading to memory disclosure [fedora-all]
Use the following template to for the 'fedpkg update' request to submit an
update for this issue as it contains the top-level parent bug(s) as well as
this tracking bug. This will ensure that all associated bugs get updated
when new packages are pushed to stable.
# bugfix, security, enhancement, newpackage (required)
type=security
# testing, stable
request=testing
# Bug numbers: 1234,9876
bugs=1468584
# Description of your update
notes=Security fix for [PUT CVEs HERE]
# Enable request automation based on the stable/unstable karma thresholds
autokarma=True
stable_karma=3
unstable_karma=-3
# Automatically close bugs when this marked as stable
close_bugs=True
# Suggest that us
Bugzilla
CVE-2017-7529 nginx: Integer overflow in nginx range filter module leading to memory disclosure
bugzilla·2017-07-07·CVSS 7.5
CVE-2017-7529 [HIGH] CVE-2017-7529 nginx: Integer overflow in nginx range filter module leading to memory disclosure
CVE-2017-7529 nginx: Integer overflow in nginx range filter module leading to memory disclosure
An integer overflow vunlerability in nginx range filter module in ngx_http_range_parse() function was found, potentially resulting in memory disclosure when used with 3rd party modules. Issue can be triggered by specially crafted http range request resulting into leaking the content of the cache file header.
Discussion:
Acknowledgments:
Name: the Nginx project
---
Patch:
https://nginx.org/download/patch.2017.ranges.txt
---
Upstream advisory:
External References:
http://mailman.nginx.org/pipermail/nginx-announce/2017/000200.html
---
Created nginx tracking bugs for this issue:
Affects: epel-all [bug 1469925]
Affects: fedora-all [bug 1469924]
---
Statement:
Red Hat Product Security
http://mailman.nginx.org/pipermail/nginx-announce/2017/000200.htmlhttp://seclists.org/fulldisclosure/2021/Sep/36http://www.securityfocus.com/bid/99534http://www.securitytracker.com/id/1039238https://access.redhat.com/errata/RHSA-2017:2538https://puppet.com/security/cve/cve-2017-7529https://support.apple.com/kb/HT212818http://mailman.nginx.org/pipermail/nginx-announce/2017/000200.htmlhttp://seclists.org/fulldisclosure/2021/Sep/36http://www.securityfocus.com/bid/99534http://www.securitytracker.com/id/1039238https://access.redhat.com/errata/RHSA-2017:2538https://puppet.com/security/cve/cve-2017-7529https://support.apple.com/kb/HT212818
2017-07-13
Published