CVE-2013-2028 describes a critical vulnerability in nginx versions 1.3.9 through 1.4.0, specifically within the ngx_http_parse_chunked function. This flaw allows remote attackers to trigger a stack-based buffer overflow and integer signedness error by sending a crafted chunked Transfer-Encoding request with a large chunk size, affecting products like F5 Nginx and Fedora Nginx. The vulnerability is highly severe, with a CVSS score of 7.5, indicating it can be exploited remotely without authentication and with low attack complexity. Successful exploitation can lead to a denial of service (crash) and potentially arbitrary code execution, posing a significant risk to affected systems. This CVE has known public exploits, including Metasploit modules and several entries on ExploitDB demonstrating denial of service and remote overflow capabilities. It has garnered significant community attention, with multiple discussions and media coverage, indicating its widespread recognition and potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.3.9, <= 1.4.0CPE matchmatch criteria | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* | ||
19CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Stack-based buffer overflow with specially crafted request
Jan 1, 2013Stack-based buffer overflow with specially crafted request
Jan 1, 2013Stack-based buffer overflow with specially crafted request
Jan 1, 2013Stack-based buffer overflow with specially crafted request
Jan 1, 2013Stack-based buffer overflow with specially crafted request
Jan 1, 2013Stack-based buffer overflow with specially crafted request
Stack-based buffer overflow with specially crafted request
Stack-based buffer overflow with specially crafted request