cbcvebase.
CVE-2011-4315
published 2011-12-08

CVE-2011-4315: Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service…

medium6.8CVSS 3.1
AVNACMAuNCPIPAP
Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.

Affected

11 ranges
VendorProductVersion rangeFixed in
debiannginx< nginx 1.1.8-1 (bookworm)nginx 1.1.8-1 (bookworm)
f5nginx>= 0 < 1.1.8-11.1.8-1
f5nginx>= 0 < 1.1.8-11.1.8-1
f5nginx>= 0 < 1.1.8-11.1.8-1
f5nginx>= 0 < 1.1.8-11.1.8-1
f5nginx>= 0.6.18 < 1.0.101.0.10
f5nginx1.1.0 – 1.1.7
fedoraprojectfedora
susestudio
susestudio_onsite
susewebyast

CVSS provenance

nvd6.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM