Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-0742

Опубликовано: 26 янв. 2016
Источник: redhat
CVSS2: 4.3
EPSS Высокий

Описание

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.

It was discovered that nginx could perform an out of bound read and dereference an invalid pointer when resolving CNAME DNS records. An attacker able to manipulate DNS responses received by nginx could use this flaw to cause a worker process to crash if nginx enabled the resolver in its configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Software Collectionsnginx16-nginxWill not fix
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-nginx18-nginxFixedRHSA-2016:142514.07.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSrh-nginx18-nginxFixedRHSA-2016:142514.07.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-nginx18-nginxFixedRHSA-2016:142514.07.2016
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nginx18-nginxFixedRHSA-2016:142514.07.2016
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSrh-nginx18-nginxFixedRHSA-2016:142514.07.2016
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSrh-nginx18-nginxFixedRHSA-2016:142514.07.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1302587nginx: invalid pointer dereference in resolver

EPSS

Процентиль: 99%
0.80364
Высокий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.

CVSS3: 7.5
nvd
почти 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.

CVSS3: 7.5
debian
почти 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remo ...

CVSS3: 7.5
github
больше 3 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.

fstec
почти 10 лет назад

Уязвимость прокси-сервера nginx, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 99%
0.80364
Высокий

4.3 Medium

CVSS2