CVE-2009-2629
nginx - arbitrary code execution
EPSS 75.1%
描述
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests.
如何修補 CVE-2009-2629
要修補 CVE-2009-2629,請將受影響套件升級到下列已修補版本。
- Debian/nginx—升級至 0.7.61-3 或更新版本
- Debian/nginx—升級至 0.4.13-2+etch2 或更新版本
CVE-2009-2629 正在被利用嗎?
可能 — EPSS 為 75.1%,屬於高被利用機率區間,建議優先修補。
受影響套件(2)
- from 0, < 0.7.61-3
- from 0, < 0.4.13-2+etch2