Vulnerability fixed in NGINX ngx_http_rewrite_module (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Heap buffer overflow in ngx_http_rewrite_module
- Denial of service via crafted HTTP requests
- Potential code execution if ASLR disabled
- Active exploitation attempts reported
"NCSC warns of a heap buffer overflow in NGINX's rewrite module. Attackers can send crafted HTTP requests to cause a denial of service. Without ASLR, remote code execution is possible. NGINX confirms active exploitation attempts."
no comments yet.