PT-2016-1408 · Nginx+3 · Nginx+3

Martin Prpič

·

Published

2016-01-26

·

Updated

2024-06-15

·

CVE-2016-0742

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions nginx versions 1.8.0 through 1.8.1 nginx versions 1.9.x through 1.9.10
Description The issue in the resolver of nginx allows remote attackers to cause a denial of service, resulting in an invalid pointer dereference and worker process crash, via a crafted UDP DNS response.
Recommendations For nginx versions 1.8.0 through 1.8.1, update to version 1.8.1 or later. For nginx versions 1.9.x through 1.9.10, update to version 1.9.10 or later. As a temporary workaround, consider restricting access to UDP DNS responses to minimize the risk of exploitation.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1070
BDU:2016-00707
CVE-2016-0742
DLA-404-1
DSA-3473-1
MGASA-2016-0065
OPENSUSE-SU-2024:10044-1
RHSA-2016:1425
SUSE-SU-2016:1232-1
USN-2892-1

Affected Products

Alt Linux
Apple Macos
Nginx
Ubuntu