CVE-2009-2629

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.

References

http://nginx.net/CHANGES-0.6

http://nginx.net/CHANGES-0.7

http://www.debian.org/security/2009/dsa-1884

http://nginx.net/CHANGES-0.5

http://www.kb.cert.org/vuls/id/180065

http://sysoev.ru/nginx/patch.180065.txt

http://nginx.net/CHANGES

https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00442.html

https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00428.html

https://www.redhat.com/archives/fedora-package-announce/2009-December/msg00449.html

Details

Source: MITRE

Published: 2009-09-15

Updated: 2021-11-10

Type: CWE-787

Risk Information

CVSS v2

Base Score: 7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 10

Severity: HIGH

Tenable Plugins

View all (10 total)

IDNameProductFamilySeverity
44749Debian DSA-1884-1 : nginx - buffer underflowNessusDebian Local Security Checks
high
43034Fedora 11 : nginx-0.7.64-1.fc11 (2009-12782)NessusFedora Local Security Checks
high
43033Fedora 10 : nginx-0.7.64-1.fc10 (2009-12775)NessusFedora Local Security Checks
high
43032Fedora 12 : nginx-0.7.64-1.fc12 (2009-12750)NessusFedora Local Security Checks
high
41608nginx HTTP Request Multiple VulnerabilitiesNessusWeb Servers
high
41022GLSA-200909-18 : nginx: Remote execution of arbitrary codeNessusGentoo Local Security Checks
high
40996Fedora 10 : nginx-0.7.62-1.fc10 (2009-9652)NessusFedora Local Security Checks
high
40995Fedora 11 : nginx-0.7.62-1.fc11 (2009-9630)NessusFedora Local Security Checks
high
40978FreeBSD : nginx -- remote denial of service vulnerability (152b27f0-a158-11de-990c-e5b1d4c882e0)NessusFreeBSD Local Security Checks
high
5174nginx HTTP Request Remote Buffer OverflowNessus Network MonitorWeb Servers
high