CVE-2020-19692: Buffer Overflow
Published Apr 4, 2023
·Updated
Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njsmoduleread in the njsmodule.c file.
Affected Software
2 affected components
Nginx njs=2019-06-27
F5 Njs<0.3.4
Event History
Apr 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of the Buffer Overflow vulnerability found in Nginx NJS?
The vulnerability ID is CVE-2020-19692.
2
What is the severity of CVE-2020-19692?
The severity of CVE-2020-19692 is critical with a score of 9.8.
3
How does the Buffer Overflow vulnerability in Nginx NJS allow a remote attacker to execute arbitrary code?
The vulnerability allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file.
4
How can I check if my version of Nginx NJS is affected?
If your version of Nginx NJS is 2019-06-27, it is affected by the vulnerability.
5
Is there a fix available for CVE-2020-19692?
Yes, a fix is available for CVE-2020-19692. It is recommended to update to a patched version of Nginx NJS.