A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
Project Subscriptions
| Vendors | Products |
|---|---|
|
F5
Subscribe
|
Nginx
Subscribe
|
|
Fedoraproject
Subscribe
|
Fedora
Subscribe
|
|
Netapp
Subscribe
|
Ontap Select Deploy Administration Utility
Subscribe
|
|
Openresty
Subscribe
|
Openresty
Subscribe
|
|
Oracle
Subscribe
|
Blockchain Platform
Subscribe
Communications Control Plane Monitor
Subscribe
Communications Fraud Monitor
Subscribe
Communications Operations Monitor
Subscribe
Communications Session Border Controller
Subscribe
Enterprise Communications Broker
Subscribe
Enterprise Session Border Controller
Subscribe
Enterprise Telephony Fraud Monitor
Subscribe
Goldengate
Subscribe
|
|
Redhat
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2670-1 | nginx security update |
Debian DSA |
DSA-4921-1 | nginx security update |
Ubuntu USN |
USN-4967-1 | nginx vulnerability |
Ubuntu USN |
USN-4967-2 | nginx vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 08 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.2::el7 cpe:/a:redhat:acm:2.4::el8 |
Mon, 19 Aug 2024 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:acm:2.4::el8 |
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: f5
Published:
Updated: 2024-08-03T18:58:26.413Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-23017
No data.
Status : Modified
Published: 2021-06-01T13:15:07.853
Modified: 2024-11-21T05:51:09.480
Link: CVE-2021-23017
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
Ubuntu USN