nginx Space String Remote Source Code Disclosure Vulnerability
BID:40434
Info
nginx Space String Remote Source Code Disclosure Vulnerability
| Bugtraq ID: | 40434 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2010 12:00AM |
| Updated: | Jun 01 2010 04:30PM |
| Credit: | Dan Crowley from Core Security Technologies |
| Vulnerable: |
Igor Sysoev nginx 0.8.32 Igor Sysoev nginx 0.8.15 Igor Sysoev nginx 0.8.14 Igor Sysoev nginx 0.7.64 Igor Sysoev nginx 0.7.62 Igor Sysoev nginx 0.7.61 Igor Sysoev nginx 0.7 |
| Not Vulnerable: |
Igor Sysoev nginx 0.8.33 Igor Sysoev nginx 0.7.65 |
Discussion
nginx Space String Remote Source Code Disclosure Vulnerability
nginx is prone to a remote source-code-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view the source code of files in the context of the server process, which may aid in further attacks.
This issue affects nginx for Microsoft Windows.
Versions prior to nginx 0.7.65 and 0.8.33 are vulnerable.
nginx is prone to a remote source-code-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view the source code of files in the context of the server process, which may aid in further attacks.
This issue affects nginx for Microsoft Windows.
Versions prior to nginx 0.7.65 and 0.8.33 are vulnerable.
Exploit / POC
nginx Space String Remote Source Code Disclosure Vulnerability
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/file.php%20
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/file.php%20
Solution / Fix
nginx Space String Remote Source Code Disclosure Vulnerability
Solution:
Updates are available; please see the references for more information.
Igor Sysoev nginx 0.7
Igor Sysoev nginx 0.7.61
Igor Sysoev nginx 0.7.62
Igor Sysoev nginx 0.7.64
Igor Sysoev nginx 0.8.14
Igor Sysoev nginx 0.8.15
Igor Sysoev nginx 0.8.32
Solution:
Updates are available; please see the references for more information.
Igor Sysoev nginx 0.7
-
Igor Sysoev nginx-0.7.65.zip
http://nginx.org/download/nginx-0.7.65.zip
Igor Sysoev nginx 0.7.61
-
Igor Sysoev nginx-0.7.65.zip
http://nginx.org/download/nginx-0.7.65.zip
Igor Sysoev nginx 0.7.62
-
Igor Sysoev nginx-0.7.65.zip
http://nginx.org/download/nginx-0.7.65.zip
Igor Sysoev nginx 0.7.64
-
Igor Sysoev nginx-0.7.65.zip
http://nginx.org/download/nginx-0.7.65.zip
Igor Sysoev nginx 0.8.14
-
Igor Sysoev nginx-0.8.33.zip
http://nginx.org/download/nginx-0.8.33.zip
Igor Sysoev nginx 0.8.15
-
Igor Sysoev nginx-0.8.33.zip
http://nginx.org/download/nginx-0.8.33.zip
Igor Sysoev nginx 0.8.32
-
Igor Sysoev nginx-0.8.33.zip
http://nginx.org/download/nginx-0.8.33.zip
References
nginx Space String Remote Source Code Disclosure Vulnerability
References:
References:
- Multiple Vulnerabilities with 8.3 Filename Pseudonyms in Web Servers (Core Security Technologies)
- nginx 0.7 Changelog (Igor Sysoev)
- nginx Changelog (Igor Sysoev)
- nginx Homepage (Igor Sysoev)
- [CORE-2010-0121] Multiple Vulnerabilities with 8.3 Filename Pseudonyms in Web Se (CORE Security Technologies Advisories
)