CVE-2013-2028
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
- Affected products
- Nginx
- f5 Nginx
- ≤ 1.4.0
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 87.5% (100th percentile)
- Weakness
- CWE-787
- NVD status
- Modified
- Published
- 2013-07-18
CVE-2013-2028 at NVD
22 known exploits for CVE-2013-2028
Proof-of-concept code and exploit modules indexed by Sploitus
nginx-1.4.0
nginxpwn
nginx-1.4.0
CVE-2013-2028-x64-bypass-ssp-and-pie-PoC
CVE-2013-2028-Exploit
CVE-2013-2028-reproduction
nginxhack
nginx 1.4.0 64-bit - Remote Exploit for Linux (Generic)
nginx 1.3.9-1.4.0 - DoS PoC
Nginx 1.4.0 (Generic Linux x64) - Remote Overflow
Nginx 1.4.0 (Generic Linux x64) - Remote Overflow
Immunity Canvas: NGINX_CHUNK
Nginx 1.3.9 / 1.4.0 Buffer Overflow
Nginx 1.3.9/1.4.0 (x86) - Brute Force
Nginx 1.3.9 < 1.4.0 - Chuncked Encoding Stack Buffer Overflow (Metasploit)
Nginx HTTP Server 1.3.9-1.4.0 Chunked Encoding Stack Buffer Overflow
Nginx HTTP Server 1.3.9-1.4.0 Chunked Encoding Stack Buffer Overflow
Nginx 1.3.9 1.4.0 - Denial of Service (PoC)
Nginx 1.3.9 < 1.4.0 - Denial of Service (PoC)
Nginx 1.3.9 / 1.4.0 Denial Of Service
nginx 'ngx_http_parse.c'栈缓冲区溢出漏洞
Nginx HTTP Server 1.3.9-1.4.0 Chunked Encoding Stack Buffer Overflow