cbcvebase.
CVE-2017-7529
published 2017-07-13

CVE-2017-7529: Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of…

high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

Affected

14 ranges
VendorProductVersion rangeFixed in
applexcode< 13.013.0
applexcode
debiannginx< nginx 1.13.3-1 (bookworm)nginx 1.13.3-1 (bookworm)
f5nginx>= 0 < 1.13.3-11.13.3-1
f5nginx>= 0 < 1.13.3-11.13.3-1
f5nginx>= 0 < 1.13.3-11.13.3-1
f5nginx>= 0 < 1.13.3-11.13.3-1
f5nginx0.5.6 – 1.12.1
f5nginx1.13.0 – 1.13.2
nginxnginx
paloaltopan-os
puppetpuppet_enterprise< 2016.4.72016.4.7
puppetpuppet_enterprise2017.1.0 – 2017.1.1
puppetpuppet_enterprise2017.2.1 – 2017.2.3

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH