Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Sep 20, 2017 | Jul 13, 2017 |
| Amazon_linux | — | Upgrade nginx | Sep 15, 2017 | Jul 11, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 13, 2017 |
| Debian | — | Upgrade nginx | Jul 13, 2017 | Jul 11, 2017 |
| Freebsd | — | Upgrade nginxUpgrade nginx-devel | Jul 12, 2017 | Jul 11, 2017 |
| Nginx | — | Upgrade to nginx version 1.12.1Upgrade to nginx version 1.13.3 | Jul 13, 2017 | Jul 13, 2017 |
| Oracle_linux | — | Upgrade olcne-nginxUpgrade nginxUpgrade olcne-utilsUpgrade nginx-mod-streamUpgrade olcnectlUpgrade olcne-agentUpgrade olcne-istio-chartUpgrade nginx-mod-http-xslt-filterUpgrade nginx-mod-http-image-filterUpgrade olcne-api-serverUpgrade nginx-mod-http-perlUpgrade olcne-prometheus-chartUpgrade nginx-all-modulesUpgrade nginx-filesystemUpgrade nginx-mod-mail | Sep 25, 2020 | Jul 11, 2017 |
| Suse | — | Upgrade vim-plugin-nginxUpgrade nginxUpgrade nginx-source | Jul 31, 2017 | Jul 11, 2017 |
| Ubuntu | — | Upgrade nginx-commonUpgrade nginx-fullUpgrade nginx-coreUpgrade nginx-extrasUpgrade nginx-light | Jul 14, 2017 | Jul 11, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 13, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub