Out-of-bounds write in nginx and NGINX Plus - CVE-2024-32760
Published: June 4, 2024
nginx
NGINX Plus
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing HTTP/3 requests within the HTTP/3 QUIC module (ngx_http_v3_module). A remote attacker can send specially crafted HTTP/3 requests to the web server, trigger an out-of-bounds write and perform a denial of service (DoS) attack.