SB2013112013 - Permissions, Privileges, and Access Controls in nginx (Alpine package)
Published: November 20, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2013-4547)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=5acaa707529521d7906adcc43f64f4b111056eba
- https://git.alpinelinux.org/aports/commit/?id=b3726212255d94d087466f1de1930eb286cbc0dd
- https://git.alpinelinux.org/aports/commit/?id=77cde2101d9aac8c10bce25425579aa239668731
- https://git.alpinelinux.org/aports/commit/?id=0a8e790578d01ba16946afac896a7351b3416295