cbcvebase.
CVE-2017-7529
published 2017-07-13

CVE-2017-7529: Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of…

PriorityP259high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
62.60%
99.1th percentile
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

Affected

14 ranges
VendorProductVersion rangeFixed in
applexcode< 13.013.0
applexcode
debiannginx< nginx 1.13.3-1 (bookworm)nginx 1.13.3-1 (bookworm)
f5nginx>= 0 < 1.13.3-11.13.3-1
f5nginx>= 0 < 1.13.3-11.13.3-1
f5nginx>= 0 < 1.13.3-11.13.3-1
f5nginx>= 0 < 1.13.3-11.13.3-1
f5nginx0.5.6 – 1.12.1
f5nginx1.13.0 – 1.13.2
nginxnginx
paloaltopan-os
puppetpuppet_enterprise< 2016.4.72016.4.7
puppetpuppet_enterprise2017.1.0 – 2017.1.1
puppetpuppet_enterprise2017.2.1 – 2017.2.3

Detection & IOCsextracted from sources · hover to see the quote

  • Attacks against CVE-2017-7529 can be blocked with Palo Alto Networks Unique Threat ID 33070 signature enabled on a firewall configured to protect vulnerable management interfaces.
  • The vulnerability is triggered by a specially crafted HTTP Range request targeting the nginx range filter module; monitor for anomalous or malformed Range headers in HTTP requests to nginx servers.
  • Nginx versions 0.5.6 through 1.13.2 (inclusive) are vulnerable; flag or alert on these version strings in server banners or package inventories.
  • ·Exploitation only leaks cache file header content when a response was served from cache; impact is limited if nginx caching is not enabled.
  • ·Memory disclosure beyond the cache file header requires the presence of third-party nginx modules; base nginx deployments have reduced exposure.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.