CVE-2013-2070: Medium severity nginx vulnerability
A similar security issue to CVE-2013-2028 was identified [1] for versions of nginx if proxypass to untrusted upstream HTTP servers are used, which could lead to a denial of service or a disclosure of a worker process' memory.
The problem affects nginx 1.1.4 - 1.2.8, 1.3.0 - 1.4.0 and was assigned the name CVE-2013-2070, so only Fedora 18 is affected.
http://nginx.org/download/patch.2013.proxy.txt
[1] http://www.openwall.com/lists/oss-security/2013/05/13/3
Other sources
http/modules/ngxhttpproxymodule.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxypass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2070?
CVE-2013-2070 is classified as a medium severity vulnerability.
How do I fix CVE-2013-2070?
To fix CVE-2013-2070, upgrade nginx to a version that is not affected by the vulnerability.
Which versions of nginx are affected by CVE-2013-2070?
CVE-2013-2070 affects nginx versions from 1.1.4 to 1.2.8 and 1.3.9 to 1.4.0.
What type of attacks can CVE-2013-2070 lead to?
CVE-2013-2070 can lead to denial of service and potential disclosure of a worker process' memory.
Which operating systems are impacted by CVE-2013-2070?
CVE-2013-2070 impacts Debian GNU/Linux versions 6.0 and 7.0.