Nginx.Request.URI.Verification.Security.Bypass

description-logoDescription

This indicates an attack attempt to exploit a remote Code Execution Vulnerability in Nginx.
The vulnerability is due to an error when vulnerable software handles a HTTP request with unescaped space characters within URIs. A remote attacker can exploit this to bypass security checks of vulnerable system, via a crafted HTTP request.

affected-products-logoAffected Products

nginx HTTP Server 1.5.x prior to 1.5.7
nginx HTTP Server 1.x prior 1.4.4

Impact logoImpact

Security Bypass: Remote attackers can bypass security checking of vulnerable systems.

recomended-action-logoRecommended Actions

Apply patch available from the website.
http://mailman.nginx.org/pipermail/nginx-announce/2013/000125.html

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)