CVE-2013-2070: Debian Linux

Medium severity, CVSS 5.8. EPSS: 11.9% chance of exploitation in the next 30 days.

http/modules/ngx_http_proxy_module.c in nginx 1.1.4 through 1.2.8 and 1.3.0 through 1.4.0, when proxy_pass is used with untrusted HTTP servers, allows remote attackers to cause a denial of service (crash) and obtain sensitive information from worker process memory via a crafted proxy response, a similar vulnerability to CVE-2013-2028.

Affected products

  • Debian Debian Linux: version 6.0 only; version 7.0 only
  • F5 Nginx: from 1.1.4, up to and including 1.2.8; from 1.3.9, up to and including 1.4.0

Published 2013-07-20. Last modified 2026-06-16.