以下是该漏洞描述信息的中文翻译: NGINX Plus 和 NGINX 开源版在 模块中存在一个漏洞。当在特定配置下使用 HTTP/3,且 OpenSSL 版本低于或等于 OpenSSL 3.5.0 时,在处理 TLS 握手过程中可能发生有限的堆缓冲区溢出。该溢出以非确定性方式发生,攻击者无法完全控制。这可能导致 NGINX 工作进程发生堆缓冲区溢出,进而导致进程重启和/或有限的数据损坏。 影响: 该漏洞可能允许远程攻击者导致 NGINX 系统发生服务中断(DoS)或有限的数据损坏。此问题仅涉及数据平面,不涉及控制
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| F5 | NGINX Open Source | 1.29.2< 1.31.6 |
affected |
1.30.4< 1.30.5 |
affected | ||
| F5 | NGINX Plus | 37.1.0.1< 37.1.1.1 |
affected |
37.0.0.1< 37.0.6.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F5 | NGINX Plus | 37.1.0.1 ~ 37.1.1.1 | - |
|
| F5 | NGINX Open Source | 1.29.2 ~ 1.31.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet