Description
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to an integer overflow vulnerability in the nginx range filter module. This vulnerability can be exploited by attackers to leak potentially sensitive information by sending specially crafted requests.
Recommendation
To mitigate this vulnerability, upgrade Nginx to the latest stable version available, which includes patches to address the integer overflow issue. Additionally, consider implementing web application firewalls (WAFs) or intrusion detection/prevention systems (IDS/IPS) to detect and block malicious requests targeting this vulnerability.
References
Could your website be exposed too?
SmartScanner can check your website for Nginx Integer Overflow and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Nginx Version Disclosure - Vulnerability
- Web Server Path Traversal - CVE-2017-14849
- Content Injection via TileJSON attribute in mapbox.js - CVE-2017-1000042
- Content Injection via TileJSON Name in mapbox.js - CVE-2017-1000043


