CVE-2014-0133: Buffer Overflow
Published Mar 28, 2014
·Updated
Heap-based buffer overflow in the SPDY implementation in nginx 1.3.15 before 1.4.7 and 1.5.x before 1.5.12 allows remote attackers to execute arbitrary code via a crafted request.
Affected Software
3 affected components
F5 Nginx>=1.3.15<1.4.7
F5 Nginx>=1.5.0<=1.5.11
openSUSE openSUSE=13.1
Event History
Mar 28, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-0133?
CVE-2014-0133 has a severity rating that indicates it could allow remote attackers to execute arbitrary code.
2
How do I fix CVE-2014-0133?
To fix CVE-2014-0133, update nginx to version 1.4.7 or later, or to version 1.5.12 or later.
3
Which versions of nginx are affected by CVE-2014-0133?
CVE-2014-0133 affects nginx versions 1.3.15 through 1.4.6 and versions 1.5.0 through 1.5.11.
4
What type of vulnerability is CVE-2014-0133?
CVE-2014-0133 is classified as a heap-based buffer overflow vulnerability.
5
Can CVE-2014-0133 be exploited remotely?
Yes, CVE-2014-0133 can be exploited by remote attackers through a crafted request.