Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Sep 20, 2017 | Apr 17, 2012 |
| Debian | — | Upgrade nginx | Jul 30, 2024 | Apr 17, 2012 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Oct 30, 2017 | Apr 17, 2012 |
| Nginx | — | Upgrade to nginx version 1.1.17Upgrade to nginx version 1.0.14 | Jan 27, 2014 | Apr 17, 2012 |
| Suse | — | Upgrade nginx-1.0-debuginfoUpgrade nginx-1.0-debugsourceUpgrade nginx-1.0 | Dec 12, 2013 | Apr 17, 2012 |
| Ubuntu | — | Upgrade nginx | Nov 19, 2024 | Apr 17, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub