The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Aug 30, 2017 | Jul 19, 2013 |
| Freebsd | — | Upgrade nginx-develUpgrade nginx | Dec 10, 2025 | May 7, 2013 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Oct 30, 2017 | Jul 19, 2013 |
| Nginx | — | Upgrade to nginx version 1.5.0Upgrade to nginx version 1.4.1 | Jan 27, 2014 | Jul 18, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub