CVE-2017-7529: Integer Overflow
An integer overflow vunlerability in nginx range filter module in ngxhttprangeparse() function was found, potentially resulting in memory disclosure when used with 3rd party modules. Issue can be triggered by specially crafted http range request resulting into leaking the content of the cache file header.
Other sources
IDE Xcode Server. Multiple issues were addressed by updating nginx to version 1.21.0.
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2017-7529?
CVE-2017-7529 is a vulnerability that affects IDE Xcode Server and was addressed by updating nginx to version 1.21.0.
How does CVE-2017-7529 affect Xcode Server?
CVE-2017-7529 affects Xcode Server by causing multiple issues that were resolved by updating nginx to version 1.21.0.
What should I do to fix CVE-2017-7529?
To fix CVE-2017-7529, you need to update nginx to version 1.21.0.
Where can I find more information about CVE-2017-7529?
You can find more information about CVE-2017-7529 on the Apple support website: https://support.apple.com/en-us/HT212818