Executive Summary

Summary
Title nginx vulnerability
Informations
Name USN-4235-2 First vendor Publication 2020-01-15
Vendor Ubuntu Last vendor Modification 2020-01-15
Severity (Vendor) N/A Revision N/A

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Overall CVSS Score 5.3
Base Score 5.3 Environmental Score 5.3
impact SubScore 1.4 Temporal Score 5.3
Exploitabality Sub Score 3.9
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction None
Scope Unchanged Confidentiality Impact Low
Integrity Impact None Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:N/A:N)
Cvss Base Score 4.3 Attack Range Network
Cvss Impact Score 2.9 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 14.04 ESM

Summary:

nginx could be made to expose sensitive information over the network.

Software Description: - nginx: small, powerful, scalable web/proxy server

Details:

USN-4235-1 fixed a vulnerability in nginx. This update provides the corresponding update for Ubuntu 14.04 ESM.

Original advisory details:

Bert JW Regeer and Francisco Oca Gonzalez discovered that nginx incorrectly
handled certain error_page configurations. A remote attacker could possibly
use this issue to perform HTTP request smuggling attacks and access
resources contrary to expectations.

Update instructions:

The problem can be corrected by updating your system to the following package versions:

Ubuntu 14.04 ESM:
nginx-common 1.4.6-1ubuntu3.9+esm1
nginx-core 1.4.6-1ubuntu3.9+esm1
nginx-extras 1.4.6-1ubuntu3.9+esm1
nginx-full 1.4.6-1ubuntu3.9+esm1
nginx-light 1.4.6-1ubuntu3.9+esm1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4235-2
https://usn.ubuntu.com/4235-1
CVE-2019-20372

Original Source

Url : http://www.ubuntu.com/usn/USN-4235-2

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 468

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2020-05-23 13:03:46
  • Multiple Updates
2020-01-15 21:19:32
  • First insertion