CVE-2017-7529
high · 7.5Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
7.5
CVSS
62.6%
EPSS (exploit prob.)
99th
EPSS percentile
2017-07-13
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-190
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| f5 | nginx | >= 0.5.6, <= 1.12.1 |
| f5 | nginx | >= 1.13.0, <= 1.13.2 |
| puppet | puppet_enterprise | < 2016.4.7 |
| puppet | puppet_enterprise | >= 2017.1.0, <= 2017.1.1 |
| puppet | puppet_enterprise | >= 2017.2.1, <= 2017.2.3 |
| apple | xcode | < 13.0 |
Check a specific version with /api/v1/cve/match.
References
- http://mailman.nginx.org/pipermail/nginx-announce/2017/000200.html
- http://seclists.org/fulldisclosure/2021/Sep/36
- http://www.securityfocus.com/bid/99534
- http://www.securitytracker.com/id/1039238
- https://access.redhat.com/errata/RHSA-2017:2538
- https://puppet.com/security/cve/cve-2017-7529
- https://support.apple.com/kb/HT212818
- http://mailman.nginx.org/pipermail/nginx-announce/2017/000200.html
- http://seclists.org/fulldisclosure/2021/Sep/36
- http://www.securityfocus.com/bid/99534
- http://www.securitytracker.com/id/1039238
- https://access.redhat.com/errata/RHSA-2017:2538
- https://puppet.com/security/cve/cve-2017-7529
- https://support.apple.com/kb/HT212818
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-7529