vulnerability

Oracle Linux: CVE-2017-7529: ELSA-2020-5859: olcne nginx security update (IMPORTANT) (Multiple Advisories)

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
2017-07-11
Added
2020-09-25
Modified
2024-12-01

Description

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
A flaw within the processing of ranged HTTP requests has been discovered in the range filter module of nginx. A remote attacker could possibly exploit this flaw to disclose parts of the cache file header, or, if used in combination with third party modules, disclose potentially sensitive memory by sending specially crafted HTTP requests.

Solution(s)

oracle-linux-upgrade-nginxoracle-linux-upgrade-nginx-all-modulesoracle-linux-upgrade-nginx-filesystemoracle-linux-upgrade-nginx-mod-http-image-filteroracle-linux-upgrade-nginx-mod-http-perloracle-linux-upgrade-nginx-mod-http-xslt-filteroracle-linux-upgrade-nginx-mod-mailoracle-linux-upgrade-nginx-mod-streamoracle-linux-upgrade-olcne-agentoracle-linux-upgrade-olcne-api-serveroracle-linux-upgrade-olcnectloracle-linux-upgrade-olcne-nginxoracle-linux-upgrade-olcne-utils
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.