nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
BID:67507
Info
nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 67507 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0088 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2014 12:00AM |
| Updated: | Mar 04 2014 12:00AM |
| Credit: | Lucas Molas |
| Vulnerable: |
Igor Sysoev nginx 1.5.10 |
| Not Vulnerable: |
Igor Sysoev nginx 1.5.11 |
Discussion
nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
nginx SPDY Implementation is prone to an arbitrary code execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application.
nginx SPDY Implementation 1.5.10 is vulnerable.
nginx SPDY Implementation is prone to an arbitrary code execution vulnerability.
An attacker can exploit this issue to execute arbitrary code in the context of the affected application.
nginx SPDY Implementation 1.5.10 is vulnerable.
Exploit / POC
nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
nginx SPDY Implementation CVE-2014-0088 Arbitrary Code Execution Vulnerability
References:
References:
- nginx Homepage (Igor Sysoev)
- [nginx-announce] nginx security advisory (CVE-2014-0088) (Nginx)