This application requires Javascript for optimal performance.

Nginx.Encoded.Directory.Traversal.DoS

Release Date

Aug 31, 2010

Severity

medium

Impact

Denial of Service: Remote attackers can crash vulnerable systems.

Description

This indicates an attack attempt against a denial-of-service vulnerability in
nginx.

This vulnerability is caused by the vulnerable software's inability to properly handle encoded directory traversal attempts. It allows remote attackers to cause a denial of service via certain encoded directory traversal sequences that trigger memory corruption.

Affected Products

nginx 0.8.36

Recommended Actions

Currently we are not aware of any patches supplied by the vendor for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2010-2266

Reference/s

http://www.exploit-db.com/exploits/13818/

Reference: VID-24003