Tracker / CVE-2012-1180
CVE-2012-1180
Medium 5.0
Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.
Affected products and versions
| debian | debian_linux |
|---|---|
| f5 | nginx · 0.1.0 → 1.0.14 |
| f5 | nginx · 1.1.0 → 1.1.17 |
| fedoraproject | fedora |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.