CVE Database
/

CVE-2020-5895

Back to search

CVE-2020-5895

Published: May 7, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

On NGINX Controller versions 3.1.0-3.3.0, AVRD uses world-readable and world-writable permissions on its socket, which allows processes or users on the local system to write arbitrary data into the socket. A local system attacker can make AVRD segmentation fault (SIGSEGV) by writing malformed messages to the socket.

VendorProductVersions

n/a

NGINX Controller

affected
< 3.4.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now