CVE-2019-7401: Buffer Overflow
NGINX Unit before 1.7.1 might allow an attacker to cause a heap-based buffer overflow in the router process with a specially crafted request. This may result in a denial of service (router process crash) or possibly have unspecified other impact.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7401?
The severity of CVE-2019-7401 is critical.
What is the potential impact of CVE-2019-7401?
CVE-2019-7401 may result in a denial of service (router process crash) or possibly have unspecified other impact.
Which software versions are affected by CVE-2019-7401?
NGINX Unit versions between 0.3 and 1.7.1 are affected by CVE-2019-7401.
How can an attacker exploit CVE-2019-7401?
An attacker can exploit CVE-2019-7401 by sending a specially crafted request to the NGINX Unit router process, causing a heap-based buffer overflow.
Are there any patches or fixes available for CVE-2019-7401?
Yes, NGINX Unit version 1.7.1 includes a fix for CVE-2019-7401. It is recommended to update to this version to mitigate the vulnerability.