CVE-2014-0088: Buffer Overflow
Published Apr 29, 2014
·Updated
The SPDY implementation in the ngxhttpspdymodule module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.
Affected Software
1 affected component
F5 Nginx=1.5.10
Remediation
Event History
Apr 29, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:38 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0088?
CVE-2014-0088 has a high severity rating due to its potential for arbitrary code execution.
2
How do I fix CVE-2014-0088?
To fix CVE-2014-0088, upgrade nginx to version 1.5.11 or later on affected systems.
3
Who is affected by CVE-2014-0088?
CVE-2014-0088 affects nginx version 1.5.10 running on 32-bit platforms.
4
What type of vulnerability is CVE-2014-0088?
CVE-2014-0088 is classified as a remote code execution vulnerability.
5
Can CVE-2014-0088 be exploited remotely?
Yes, CVE-2014-0088 can be exploited remotely via crafted requests to the server.