PT-2016-1408 · Nginx+3 · Nginx+3

Martin Prpič

·

Publicado

2016-01-26

·

Atualizado

2024-06-15

·

CVE-2016-0742

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions nginx versions 1.8.0 through 1.8.1 nginx versions 1.9.x through 1.9.10
Description The issue in the resolver of nginx allows remote attackers to cause a denial of service, resulting in an invalid pointer dereference and worker process crash, via a crafted UDP DNS response.
Recommendations For nginx versions 1.8.0 through 1.8.1, update to version 1.8.1 or later. For nginx versions 1.9.x through 1.9.10, update to version 1.9.10 or later. As a temporary workaround, consider restricting access to UDP DNS responses to minimize the risk of exploitation.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1070
BDU:2016-00707
CVE-2016-0742
DLA-404-1
DSA-3473-1
MGASA-2016-0065
OPENSUSE-SU-2024:10044-1
RHSA-2016:1425
SUSE-SU-2016:1232-1
USN-2892-1

Produtos afetados

Alt Linux
Apple Macos
Nginx
Ubuntu