CVE-2017-7529
nginx - security update
7.5
HIGH
CVSS 3.1
EPSS 91.9%
Description
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
How to fix CVE-2017-7529
To remediate CVE-2017-7529, upgrade the affected package to a fixed version below.
- Alpine/nginx—upgrade to 1.12.1-r0 or later
- —upgrade to 1.13.3-1 or later
- —upgrade to 1.2.1-2.2+wheezy4+deb7u1 or later
- —upgrade to 1.6.2-5+deb8u5 or later
Is CVE-2017-7529 being exploited?
Likely — EPSS is 91.9%, placing CVE-2017-7529 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (4)
- from 0, < 1.12.1-r0
- from 0, < 1.13.3-1
- from 0, < 1.2.1-2.2+wheezy4+deb7u1
- from 0, < 1.6.2-5+deb8u5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |