CVE Database
/

CVE-2012-1180

Back to search

CVE-2012-1180

Published: Apr 17, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

Use-after-free vulnerability in nginx before 1.0.14 and 1.1.x before 1.1.17 allows remote HTTP servers to obtain sensitive information from process memory via a crafted backend response, in conjunction with a client request.

VendorProductVersions

n/a

n/a

affected
n/a

References

openSUSE-SU-2012:0469
vendor-advisory
x_refsource_SUSE
80124
vdb-entry
x_refsource_OSVDB
DSA-2434
vendor-advisory
x_refsource_DEBIAN
FEDORA-2012-4006
vendor-advisory
x_refsource_FEDORA
48465
third-party-advisory
x_refsource_SECUNIA
48577
third-party-advisory
x_refsource_SECUNIA
FEDORA-2012-3846
vendor-advisory
x_refsource_FEDORA
FEDORA-2012-3991
vendor-advisory
x_refsource_FEDORA
MDVSA-2012:043
vendor-advisory
x_refsource_MANDRIVA
GLSA-201203-22
vendor-advisory
x_refsource_GENTOO
1026827
vdb-entry
x_refsource_SECTRACK
52578
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now