First published: Tue Apr 29 2014(Updated: )
The SPDY implementation in the ngx_http_spdy_module module in nginx 1.5.10 before 1.5.11, when running on a 32-bit platform, allows remote attackers to execute arbitrary code via a crafted request.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nginx | =1.5.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0088 has a high severity rating due to its potential for arbitrary code execution.
To fix CVE-2014-0088, upgrade nginx to version 1.5.11 or later on affected systems.
CVE-2014-0088 affects nginx version 1.5.10 running on 32-bit platforms.
CVE-2014-0088 is classified as a remote code execution vulnerability.
Yes, CVE-2014-0088 can be exploited remotely via crafted requests to the server.