cbcvebase.
CVE-2016-0742
published 2016-02-15

CVE-2016-0742: The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process…

PriorityP352high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
81.96%
99.6th percentile
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response.

Affected

17 ranges
VendorProductVersion rangeFixed in
applexcode< 13.013.0
applexcode
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debiannginx< nginx 1.9.10-1 (bookworm)nginx 1.9.10-1 (bookworm)
f5nginx>= 0 < 1.9.10-11.9.10-1
f5nginx>= 0 < 1.9.10-11.9.10-1
f5nginx>= 0 < 1.9.10-11.9.10-1
f5nginx>= 0 < 1.9.10-11.9.10-1
f5nginx>= 0 < 1.4.6-1ubuntu3.41.4.6-1ubuntu3.4
f5nginx>= 0.6.18 < 1.8.11.8.1
f5nginx>= 1.9.0 < 1.9.101.9.10
opensuseleap
redhatsoftware_collections

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is only exploitable when the 'resolver' directive is present in the nginx configuration file — detection should check for active resolver usage in nginx configs.
  • Attack vector is a crafted UDP DNS response sent to the nginx worker process; monitor for unexpected nginx worker process crashes correlated with DNS resolver activity.
  • The flaw involves out-of-bounds read and invalid pointer dereference when processing CNAME DNS records; anomalous/malformed CNAME responses to nginx's resolver port may indicate exploitation attempts.
  • ·Vulnerability is only present and exploitable in nginx versions before 1.8.1 and 1.9.x before 1.9.10; verify installed version before triaging alerts.
  • ·Red Hat marked nginx16-nginx (Red Hat Software Collections) as 'Will not fix', meaning patched packages may not be available for all RHEL configurations — manual version checks are required.
  • ·The upstream fix is tracked in a specific nginx changeset; use this to verify patch application in source-built deployments.

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.