6.8

CVE-2011-4315

Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
F5 ≫ Nginx Version >= 0.6.18 < 1.0.10
F5 ≫ Nginx Version >= 1.1.0 <= 1.1.7
Fedoraproject ≫ Fedora Version 16
Suse ≫ Studio Version 1.2 SwEdition standard
Suse ≫ Studio Onsite Version 1.2
Suse ≫ Webyast Version 1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.96% 0.925
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

http://secunia.com/advisories/48577
Third Party Advisory
http://security.gentoo.org/glsa/glsa-201203-22.xml
Third Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2011-December/070569.html
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2011-12/msg00005.html
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2011/11/17/10
Patch
Third Party Advisory
Mailing List
http://openwall.com/lists/oss-security/2011/11/17/8
Patch
Third Party Advisory
Mailing List
http://secunia.com/advisories/47097
Third Party Advisory
http://trac.nginx.org/nginx/changeset/4268/nginx
Patch
Vendor Advisory
Issue Tracking
http://www.nginx.org/en/CHANGES-1.0
Vendor Advisory
Release Notes
http://www.securityfocus.com/bid/50710
Third Party Advisory
VDB Entry