CVE-2012-1180 describes a use-after-free vulnerability in NGINX versions prior to 1.0.14 and 1.1.x prior to 1.1.17, impacting various Debian and Fedora distributions. This flaw allows a remote HTTP server to potentially extract sensitive information from NGINX process memory when processing a crafted backend response in conjunction with a client request. With a CVSS score of 5.0, it is a medium-severity vulnerability, requiring no authentication and having low attack complexity, but only resulting in partial confidentiality impact. There is no evidence of active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.1.0, < 1.0.14CPE matchmatch criteria | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* | ||
>= 1.1.0, < 1.1.17CPE matchmatch criteria | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* | ||
15CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:15:*:*:*:*:*:*:* | ||
16CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:16:*:*:*:*:*:*:* | ||
17CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Memory disclosure with specially crafted backend responses
Jan 1, 2012Memory disclosure with specially crafted backend responses
Jan 1, 2012Memory disclosure with specially crafted backend responses
Jan 1, 2012Memory disclosure with specially crafted backend responses
Jan 1, 2012Memory disclosure with specially crafted backend responses
Jan 1, 2012Memory disclosure with specially crafted backend responses
Memory disclosure with specially crafted backend responses
Memory disclosure with specially crafted backend responses