2018-07-28
ALT-BU-2018-3372-1
Branch p8 update bulletin.
Closed vulnerabilities
Published: 2017-08-28
BDU:2021-04615
Уязвимость модуля autoindex сервера NGINX, связанная с целочисленным переполнением, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Severity: CRITICAL (9.8)
Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
Published: 2021-06-07
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-20005
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
Severity: CRITICAL (9.8)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References:
- http://nginx.org/en/CHANGES
- http://nginx.org/en/CHANGES
- https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccf
- https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccf
- https://github.com/nginx/nginx/commit/b900cc28fcbb4cf5a32ab62f80b59292e1c85b4b
- https://github.com/nginx/nginx/commit/b900cc28fcbb4cf5a32ab62f80b59292e1c85b4b
- [debian-lts-announce] 20210607 [SECURITY] [DLA 2680-1] nginx security update
- [debian-lts-announce] 20210607 [SECURITY] [DLA 2680-1] nginx security update
- https://security.netapp.com/advisory/ntap-20210805-0006/
- https://security.netapp.com/advisory/ntap-20210805-0006/
- https://trac.nginx.org/nginx/ticket/1368
- https://trac.nginx.org/nginx/ticket/1368
Published: 2017-07-13
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2017-7529
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
Severity: HIGH (7.5)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References:
- [nginx-announce] 20170711 nginx security advisory (CVE-2017-7529)
- [nginx-announce] 20170711 nginx security advisory (CVE-2017-7529)
- 20210921 APPLE-SA-2021-09-20-4 Xcode 13
- 20210921 APPLE-SA-2021-09-20-4 Xcode 13
- 99534
- 99534
- 1039238
- 1039238
- RHSA-2017:2538
- RHSA-2017:2538
- https://puppet.com/security/cve/cve-2017-7529
- https://puppet.com/security/cve/cve-2017-7529
- https://support.apple.com/kb/HT212818
- https://support.apple.com/kb/HT212818