Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Sep 20, 2017 | Jul 13, 2017 |
| Amazon_linux | — | Upgrade nginx | Sep 15, 2017 | Jul 11, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 13, 2017 |
| Debian | — | Upgrade nginx | Jul 13, 2017 | Jul 11, 2017 |
| Freebsd | — | Upgrade nginx-develUpgrade nginx | Jul 12, 2017 | Jul 11, 2017 |
| Nginx | — | Upgrade to nginx version 1.12.1Upgrade to nginx version 1.13.3 | Jul 13, 2017 | Jul 13, 2017 |
| Oracle_linux | — | Upgrade nginx-mod-http-image-filterUpgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade olcne-istio-chartUpgrade olcne-utilsUpgrade nginxUpgrade olcne-nginxUpgrade olcne-agentUpgrade olcnectlUpgrade olcne-api-serverUpgrade nginx-mod-http-perlUpgrade nginx-mod-mailUpgrade olcne-prometheus-chartUpgrade nginx-filesystemUpgrade nginx-all-modules | Sep 25, 2020 | Jul 11, 2017 |
| Suse | — | Upgrade nginx-sourceUpgrade vim-plugin-nginxUpgrade nginx | Jul 31, 2017 | Jul 11, 2017 |
| Ubuntu | — | Upgrade nginx-commonUpgrade nginx-coreUpgrade nginx-fullUpgrade nginx-lightUpgrade nginx-extras | Jul 14, 2017 | Jul 11, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 13, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub