Oval Definition:oval:com.ubuntu.precise:def:20132028000
Revision Date:2013-07-19Version:1
Title:CVE-2013-2028 on Ubuntu 12.04 LTS (precise) - high.
Description:The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2013-2028
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND While related to the CVE in some way, the 'nginx' package in precise is not affected (note: 'code not present').
  • BACK