Описание
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
A flaw was found in nginx. An off-by-one error while processing DNS responses allows a network attacker to write a dot character out of bounds in a heap allocated buffer which can allow overwriting the least significant byte of next heap chunk metadata likely leading to a remote code execution in certain circumstances. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 8 | nginx:1.14/nginx | Will not fix | ||
Red Hat Enterprise Linux 9 | nginx | Not affected | ||
3scale API Management 2.11 on RHEL 7 | 3scale-amp2/3scale-rhel7-operator | Fixed | RHSA-2021:3851 | 14.10.2021 |
3scale API Management 2.11 on RHEL 7 | 3scale-amp2/3scale-rhel7-operator-metadata | Fixed | RHSA-2021:3851 | 14.10.2021 |
3scale API Management 2.11 on RHEL 7 | 3scale-amp2/apicast-rhel7-operator | Fixed | RHSA-2021:3851 | 14.10.2021 |
3scale API Management 2.11 on RHEL 7 | 3scale-amp2/apicast-rhel7-operator-metadata | Fixed | RHSA-2021:3851 | 14.10.2021 |
3scale API Management 2.11 on RHEL 7 | 3scale-amp2/memcached-rhel7 | Fixed | RHSA-2021:3851 | 14.10.2021 |
3scale API Management 2.11 on RHEL 7 | 3scale-amp2/system-rhel7 | Fixed | RHSA-2021:3851 | 14.10.2021 |
3scale API Management 2.11 on RHEL 8 | 3scale-amp2/apicast-gateway-rhel8 | Fixed | RHSA-2021:3851 | 14.10.2021 |
3scale API Management 2.11 on RHEL 8 | 3scale-amp2/backend-rhel8 | Fixed | RHSA-2021:3851 | 14.10.2021 |
Показывать по
Дополнительная информация
Статус:
EPSS
8.1 High
CVSS3
Связанные уязвимости
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
A security issue in nginx resolver was identified, which might allow a ...
EPSS
8.1 High
CVSS3