Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade nginx | Sep 20, 2017 | Jul 13, 2017 |
| Amazon_linux | — | Upgrade nginx | Sep 15, 2017 | Jul 11, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 13, 2017 |
| Debian | — | Upgrade nginx | Jul 13, 2017 | Jul 11, 2017 |
| Freebsd | — | Upgrade nginx-develUpgrade nginx | Jul 12, 2017 | Jul 11, 2017 |
| Nginx | — | Upgrade to nginx version 1.12.1Upgrade to nginx version 1.13.3 | Jul 13, 2017 | Jul 13, 2017 |
| Oracle_linux | — | Upgrade olcne-utilsUpgrade nginx-mod-http-image-filterUpgrade nginxUpgrade olcnectlUpgrade olcne-agentUpgrade olcne-api-serverUpgrade olcne-istio-chartUpgrade nginx-mod-streamUpgrade nginx-mod-http-xslt-filterUpgrade olcne-nginxUpgrade nginx-all-modulesUpgrade olcne-prometheus-chartUpgrade nginx-mod-mailUpgrade nginx-mod-http-perlUpgrade nginx-filesystem | Sep 25, 2020 | Jul 11, 2017 |
| Suse | — | Upgrade nginxUpgrade nginx-sourceUpgrade vim-plugin-nginx | Jul 31, 2017 | Jul 11, 2017 |
| Ubuntu | — | Upgrade nginx-lightUpgrade nginx-extrasUpgrade nginx-commonUpgrade nginx-coreUpgrade nginx-full | Jul 14, 2017 | Jul 11, 2017 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 13, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub