Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-0747

Опубликовано: 26 янв. 2016
Источник: redhat
CVSS2: 4.3

Описание

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

It was discovered that nginx did not limit recursion when resolving CNAME DNS records. An attacker able to manipulate DNS responses received by nginx could use this flaw to cause a worker process to use an excessive amount of resources if nginx enabled the resolver in its configuration.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Software Collectionsnginx16-nginxWill not fix
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-nginx18-nginxFixedRHSA-2016:142514.07.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUSrh-nginx18-nginxFixedRHSA-2016:142514.07.2016
Red Hat Software Collections for Red Hat Enterprise Linux 6.7 EUSrh-nginx18-nginxFixedRHSA-2016:142514.07.2016
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-nginx18-nginxFixedRHSA-2016:142514.07.2016
Red Hat Software Collections for Red Hat Enterprise Linux 7.1 EUSrh-nginx18-nginxFixedRHSA-2016:142514.07.2016
Red Hat Software Collections for Red Hat Enterprise Linux 7.2 EUSrh-nginx18-nginxFixedRHSA-2016:142514.07.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1302589nginx: Insufficient limits of CNAME resolution in resolver

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

CVSS3: 5.3
nvd
почти 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

CVSS3: 5.3
debian
почти 10 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not pr ...

CVSS3: 5.3
github
больше 3 лет назад

The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.

suse-cvrf
около 10 лет назад

Security update for nginx

4.3 Medium

CVSS2