imPC@ndo IT

Tracker / CVE-2017-7529

CVE-2017-7529

High 7.5

Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.

Affected products and versions

apple xcode · … → 13.0
f5 nginx · 0.5.6 → 1.12.1
f5 nginx · 1.13.0 → 1.13.2
puppet puppet_enterprise · … → 2016.4.7
puppet puppet_enterprise · 2017.1.0 → 2017.1.1
puppet puppet_enterprise · 2017.2.1 → 2017.2.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References