Out-of-bounds write in NGINX Plus and NGINX Open Source - CVE-2024-32760

 

Out-of-bounds write in NGINX Plus and NGINX Open Source - CVE-2024-32760

Published: June 4, 2024


Vulnerability identifier: #VU90993
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-32760
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing HTTP/3 requests within the HTTP/3 QUIC module (ngx_http_v3_module). A remote attacker can send specially crafted HTTP/3 requests to the web server, trigger an out-of-bounds write and perform a denial of service (DoS) attack.


Affected software

NGINX Plus
NGINX Open Source
Oracle Communications Operations Monitor
Sensor Proxy
IBM Watson Discovery for IBM Cloud Pak for Data

How to mitigate CVE-2024-32760

Install updates from vendor's website.

NGINX Plus - addressed in versions R31 P2, R32
NGINX Open Source - update to 1.26.1
Sensor Proxy - update to 1.4.0
IBM Watson Discovery for IBM Cloud Pak for Data - addressed in versions 4.8.6, 5.0.1

External References

Related Security Bulletins