#VU56735 NULL pointer dereference in nginx - CVE-2016-0742
Published: September 21, 2021
nginx
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within resolver in nginx when processing UDP DNS packets. A remote attacker can send a specially crafted UDP DNS response to the application and perform a denial of service (DoS) attack.
Remediation
External links
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html
- http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html
- http://www.debian.org/security/2016/dsa-3473
- http://www.securitytracker.com/id/1034869
- http://www.ubuntu.com/usn/USN-2892-1
- https://access.redhat.com/errata/RHSA-2016:1425
- https://bto.bluecoat.com/security-advisory/sa115
- https://bugzilla.redhat.com/show_bug.cgi?id=1302587
- https://security.gentoo.org/glsa/201606-06