os/unix/ngx_files.c in nginx before 1.10.1 and 1.11.x before 1.11.1 allows remote attackers to cause a denial of service (NULL pointer dereference and worker process crash) via a crafted request, involving writing a client request body to a temporary file.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Sep 20, 2017 | Jun 7, 2016 |
| Amazon_linux | — | Upgrade nginx | Jun 15, 2016 | Jun 7, 2016 |
| Debian | — | Upgrade nginx | Jun 1, 2016 | Jun 1, 2016 |
| Freebsd | — | Upgrade nginxUpgrade nginx-devel | Dec 10, 2025 | May 31, 2016 |
| Gentoo Linux | — | Upgrade www-servers/nginx. | Oct 30, 2017 | Jun 7, 2016 |
| Nginx | — | Upgrade to nginx version 1.10.1Upgrade to nginx version 1.11.1 | Jun 7, 2016 | Jun 7, 2016 |
| Panos | — | Update PAN-OS 8.0 to the latest workaround for your deviceUpdate PAN-OS 7.1 to the latest workaround for your deviceUpdate PAN-OS 9.0 to the latest workaround for your deviceUpdate PAN-OS 8.1 to the latest workaround for your device | Jun 17, 2020 | Jun 17, 2020 |
| Suse | — | Upgrade nginx-sourceUpgrade nginx | Feb 2, 2017 | Jun 7, 2016 |
| Ubuntu | — | Upgrade nginx-fullUpgrade nginx-coreUpgrade nginx-extrasUpgrade nginx-light | Jun 2, 2016 | Jun 2, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub