Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2013-2028

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.922
EPSS Ranking 99.7%
CVSS Severity
CVSS v2 Score 7.5
References
Products affected by CVE-2013-2028
  • F5 » Nginx » Version: 1.3.10
    cpe:2.3:a:f5:nginx:1.3.10
  • F5 » Nginx » Version: 1.3.11
    cpe:2.3:a:f5:nginx:1.3.11
  • F5 » Nginx » Version: 1.3.12
    cpe:2.3:a:f5:nginx:1.3.12
  • F5 » Nginx » Version: 1.3.13
    cpe:2.3:a:f5:nginx:1.3.13
  • F5 » Nginx » Version: 1.3.14
    cpe:2.3:a:f5:nginx:1.3.14
  • F5 » Nginx » Version: 1.3.15
    cpe:2.3:a:f5:nginx:1.3.15
  • F5 » Nginx » Version: 1.3.16
    cpe:2.3:a:f5:nginx:1.3.16
  • F5 » Nginx » Version: 1.3.9
    cpe:2.3:a:f5:nginx:1.3.9
  • F5 » Nginx » Version: 1.4.0
    cpe:2.3:a:f5:nginx:1.4.0
  • Fedoraproject » Fedora » Version: 19
    cpe:2.3:o:fedoraproject:fedora:19


Contact Us

Shodan ® - All rights reserved