FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The VUXML data was last processed by FreshPorts on 2024-05-02 04:12:46 UTC

List all Vulnerabilities, by package

List all Vulnerabilities, by date

k68

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
c1202de8-4b29-11ea-9673-4c72b94353b5NGINX -- HTTP request smuggling

NGINX Team reports:

NGINX before 1.17.7, with certain error_page configurations, allows HTTP request smuggling, as demonstrated by the ability of an attacker to read unauthorized web pages in environments where NGINX is being fronted by a load balancer.


Discovery 2019-12-10
Entry 2020-02-09
nginx
< 1.16.1_11,2

nginx-devel
< 1.17.7

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20372
CVE-2019-20372
676d4f16-4fb3-11ed-a374-8c164567ca3cnginx -- Two vulnerabilities

NGINX Development Team reports:

Two security issues were identified in the ngx_http_mp4_module, which might allow an attacker to cause a worker process crash or worker process memory disclosure by using a specially crafted mp4 file, or might have potential other impact (CVE-2022-41741, CVE-2022-41742).


Discovery 2022-10-19
Entry 2022-10-19
nginx
ge 1.0.7 lt 1.22.1

nginx-devel
ge 1.1.3 lt 1.23.2

CVE-2022-41741
CVE-2022-41742
https://mailman.nginx.org/archives/list/nginx@nginx.org/thread/F7TMIHDNNU3M52GYS23UWDWW2R2BLVVH/
0882f019-bd60-11eb-9bdd-8c164567ca3cNGINX -- 1-byte memory overwrite in resolver

NGINX team reports:

1-byte memory overwrite might occur during DNS server response processing if the "resolver" directive was used, allowing an attacker who is able to forge UDP packets from the DNS server to cause worker process crash or, potentially, arbitrary code execution.


Discovery 2021-05-25
Entry 2021-05-25
nginx
< 1.20.1,2

nginx-devel
< 1.21.0

CVE-2021-23017
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23017