Resource exhaustion in NGINX Open Source - CVE-2016-0747
Published: September 21, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly limit the CNAME resolution within resolver component. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack by send a specially crafted DNS response.
Affected software
Fedora
Junos OS
nginx
rh-nginx18-nginx (Red Hat package)
PowerFlex rack
How to mitigate CVE-2016-0747
Junos OS - addressed in versions 21.4R3-S8, 22.2R3-S5, 22.3R3-S3, 22.4R3-S4, 23.2R2-S2, 23.4R2-S1, 24.2R1
nginx - addressed in versions 1.6.3-8.el7, 1.8.1-1.fc22, 1.8.1-1.fc23, 1.10.1-1.el5, 1.10.1-1.el6
rh-nginx18-nginx (Red Hat package) - addressed in versions 1.8.1-1.el6, 1.8.1-1.el7
PowerFlex rack - update to 3.6.6.0
External References
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html
- http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html
- http://www.debian.org/security/2016/dsa-3473
- http://www.securitytracker.com/id/1034869
- http://www.ubuntu.com/usn/USN-2892-1
- https://access.redhat.com/errata/RHSA-2016:1425
- https://bto.bluecoat.com/security-advisory/sa115
- https://bugzilla.redhat.com/show_bug.cgi?id=1302589
- https://security.gentoo.org/glsa/201606-06
Related Security Bulletins
- Multiple vulnerabilities in nginx
- Multiple vulnerabilities in Dell PowerFlex Rack
- Multiple vulnerabilities in Dell PowerFlex Appliance
- Junos OS update for nginx
- Fedora 23 update for nginx
- Fedora 22 update for nginx
- Fedora EPEL 7 update for nginx
- Fedora EPEL 6 update for nginx
- Fedora EPEL 5 update for nginx
- Red Hat Software Collections update for rh-nginx18-nginx