nginx...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

BUGTRAQ ID: 36839 CVE(CAN) ID: CVE-2009-3896 nginx是多平台的HTTP服务器和邮件代理服务器。 nginx服务器的src/http/ngx_http_parse.c文件的ngx_http_process_request_headers()函数中存在空指针引用错误,远程攻击者可以通过超长的URI来触发这个漏洞,导致worker进程崩溃。 Igor Sysoev nginx 0.8.x Igor Sysoev nginx 0.7.x Igor Sysoev nginx 0.6.x Igor Sysoev nginx 0.5.x Igor Sysoev nginx 0.4.x 厂商补丁: Debian ------ Debian已经为此发布了一个安全公告(DSA-1920-1)以及相应补丁: DSA-1920-1:New nginx packages fix denial of service 链接:http://www.debian.org/security/2009/dsa-1920 补丁下载: Source archives: http://security.debian.org/pool/updates/main/n/nginx/nginx_0.4.13.orig.tar.gz Size/MD5 checksum: 436610 d385a1e7a23020d421531818d5606b5b http://security.debian.org/pool/updates/main/n/nginx/nginx_0.4.13-2+etch3.dsc Size/MD5 checksum: 611 c4e1baf967a3dbb19a28bf2da8c32fdb http://security.debian.org/pool/updates/main/n/nginx/nginx_0.4.13-2+etch3.diff.gz Size/MD5 checksum: 6822 794447a883501912bf6f448b9a561293 alpha architecture (DEC Alpha)...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息