REDHAT-BUG-962525: Medium severity nginx vulnerability
A similar security issue to CVE-2013-2028 was identified [1] for versions of nginx if proxypass to untrusted upstream HTTP servers are used, which could lead to a denial of service or a disclosure of a worker process' memory.
The problem affects nginx 1.1.4 - 1.2.8, 1.3.0 - 1.4.0 and was assigned the name CVE-2013-2070, so only Fedora 18 is affected.
http://nginx.org/download/patch.2013.proxy.txt
[1] http://www.openwall.com/lists/oss-security/2013/05/13/3
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-962525?
The severity of REDHAT-BUG-962525 is considered high due to its potential to cause denial of service and memory disclosure.
What software versions are affected by REDHAT-BUG-962525?
REDHAT-BUG-962525 affects Nginx versions between 1.1.4 and 1.2.8, as well as between 1.3.0 and 1.4.0.
How do I fix REDHAT-BUG-962525?
To fix REDHAT-BUG-962525, update your Nginx installation to a version that is not affected by this vulnerability.
What kind of attack does REDHAT-BUG-962525 facilitate?
REDHAT-BUG-962525 can facilitate denial of service attacks and unauthorized memory disclosures from Nginx worker processes.
Is there a workaround for REDHAT-BUG-962525?
A recommended workaround for REDHAT-BUG-962525 is to avoid using proxy_pass with untrusted upstream HTTP servers.