Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-0747

Опубликовано: 15 фев. 2016
Источник: nvd
CVSS3: 5.3
CVSS2: 5
EPSS Средний

Описание

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
Версия от 0.6.18 (включая) до 1.8.1 (исключая)
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
Версия от 1.9.0 (включая) до 1.9.10 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
Конфигурация 5
cpe:2.3:a:apple:xcode:*:*:*:*:*:*:*:*
Версия до 13.0 (исключая)

EPSS

Процентиль: 97%
0.33182
Средний

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

redhat
около 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

CVSS3: 5.3
debian
почти 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not pr ...

CVSS3: 5.3
github
больше 3 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

suse-cvrf
около 10 лет назад

Security update for nginx

EPSS

Процентиль: 97%
0.33182
Средний

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-400