Integer overflow in NGINX Open Source - CVE-2017-7529
Published: July 11, 2017 / Updated: December 19, 2023
Vulnerability identifier: #VU7410
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7529
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to integer overflow when processing specially crafted requests. A remote attacker can send a malicious request to vulnerable server and gain access to potentially sensitive information.
When using nginx with standard modules this allows an attacker to obtain a cache file header if a response was returned from cache. In some configurations a cache file header may contain IP address of the backend server or other sensitive information.
The vulnerability exists due to integer overflow when processing specially crafted requests. A remote attacker can send a malicious request to vulnerable server and gain access to potentially sensitive information.
When using nginx with standard modules this allows an attacker to obtain a cache file header if a response was returned from cache. In some configurations a cache file header may contain IP address of the backend server or other sensitive information.
Affected software
NGINX Open Source
Debian Linux
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Fedora
Palo Alto PAN-OS
Ubuntu
Junos OS
nginx (Alpine package)
nginx
PowerFlex rack
IBM Maximo Application Suite
Debian Linux
Arch Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Fedora
Palo Alto PAN-OS
Ubuntu
Junos OS
nginx (Alpine package)
nginx
PowerFlex rack
IBM Maximo Application Suite
How to mitigate CVE-2017-7529
Update to version 1.13.3 or 1.12.1.
NGINX Open Source - addressed in versions 1.12.1, 1.13.3
nginx (Alpine package) - update to 1.8.1-r2
Palo Alto PAN-OS - addressed in versions 7.1.26, 8.1.13, 9.0.6
Junos OS - addressed in versions 21.4R3-S8, 22.2R3-S5, 22.3R3-S3, 22.4R3-S4, 23.2R2-S2, 23.4R2-S1, 24.2R1
nginx - addressed in versions 1.12.1-1.fc25, 1.12.1-1.fc26, 1.12.2-1.el7
PowerFlex rack - update to 3.6.6.0
IBM Maximo Application Suite - addressed in versions 8.10.8, 8.11.5
nginx (Alpine package) - update to 1.8.1-r2
Palo Alto PAN-OS - addressed in versions 7.1.26, 8.1.13, 9.0.6
Junos OS - addressed in versions 21.4R3-S8, 22.2R3-S5, 22.3R3-S3, 22.4R3-S4, 23.2R2-S2, 23.4R2-S1, 24.2R1
nginx - addressed in versions 1.12.1-1.fc25, 1.12.1-1.fc26, 1.12.2-1.el7
PowerFlex rack - update to 3.6.6.0
IBM Maximo Application Suite - addressed in versions 8.10.8, 8.11.5
Links to Public Exploits and PoC-codes
- Exploit #9444 - -Exploit-CVE-2017-7529 (CVE-2017-7529: Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially craf (December 19, 2023)
- Exploit #6675 - CVE-2017-7529-Nginx---Remote-Integer-Overflow-Exploit () (September 1, 2021)
- Exploit #5048 - exploit-nginx-1.10.3 (CVE-2017-7529 | nginx on the range 0.5.6 - 1.13.2) (January 20, 2021)
- Exploit #3035 - CVE-2017-7529 (Exploit for NGiX 1.6.2 Remote Integer Overflow Vulnerability CVE-2017-7529) (June 19, 2020)
External References
Related Security Bulletins
- Integer overflow in nginx
- Arch Linux update for nginx
- Debian update for nginx
- Ubuntu update for nginx
- Red Hat update for nginx
- Amazon Linux AMI update for nginx
- Multiple vulnerabilities in Palo Alto Networks PAN-OS
- Integer overflow in nginx (Alpine package)
- Integer overflow in IBM Maximo Application Suite
- Multiple vulnerabilities in Dell PowerFlex Rack
- Multiple vulnerabilities in Dell PowerFlex Appliance
- Junos OS update for nginx
- Fedora 25 update for nginx
- Fedora 26 update for nginx
- Fedora EPEL 7 update for nginx