Loading
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.
Use CWE-787, F5 vendor hub and Nginx product page to widen CVE-2013-2028 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-44487, CVE-2017-20005 and CVE-2021-23017 for nearby disclosures in the same product family.