#VU56737 Resource exhaustion in nginx - CVE-2016-0747
Published: September 21, 2021
nginx
F5 Networks
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly limit the CNAME resolution within resolver component. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack by send a specially crafted DNS response.
Remediation
External links
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html
- http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html
- http://www.debian.org/security/2016/dsa-3473
- http://www.securitytracker.com/id/1034869
- http://www.ubuntu.com/usn/USN-2892-1
- https://access.redhat.com/errata/RHSA-2016:1425
- https://bto.bluecoat.com/security-advisory/sa115
- https://bugzilla.redhat.com/show_bug.cgi?id=1302589
- https://security.gentoo.org/glsa/201606-06