CVE-2016-0747
published 2016-02-15CVE-2016-0747: The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service…
PriorityP335medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
8.43%
94.4th percentile
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 13.0 | 13.0 |
| apple | xcode | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | nginx | < nginx 1.9.10-1 (bookworm) | nginx 1.9.10-1 (bookworm) |
| f5 | nginx | >= 0 < 1.9.10-1 | 1.9.10-1 |
| f5 | nginx | >= 0 < 1.9.10-1 | 1.9.10-1 |
| f5 | nginx | >= 0 < 1.9.10-1 | 1.9.10-1 |
| f5 | nginx | >= 0 < 1.9.10-1 | 1.9.10-1 |
| f5 | nginx | >= 0 < 1.4.6-1ubuntu3.4 | 1.4.6-1ubuntu3.4 |
| f5 | nginx | >= 0.6.18 < 1.8.1 | 1.8.1 |
| f5 | nginx | >= 1.9.0 < 1.9.10 | 1.9.10 |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2016-0747: Xcode 13
vendor_apple·2021-09-20·CVSS 5.3
CVE-2016-0747 [MEDIUM] CVE-2016-0747: Xcode 13
Apple Security Update: About the security content of Xcode 13
Product: Xcode
Version: 13
CVE: CVE-2016-0747
Component: CVE-2016-0747
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2016-02-09·CVSS 7.5
CVE-2016-0742 [HIGH] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx incorrectly handled certain DNS server
responses when the resolver is enabled. A remote attacker could possibly
use this issue to cause nginx to crash, resulting in a denial of service.
(CVE-2016-0742)
It was discovered that nginx incorrectly handled CNAME response processing
when the resolver is enabled. A remote attacker could use this issue to
cause nginx to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2016-0746)
It was discovered that nginx incorrectly handled CNAME resolution when
the resolver is enabled. A remote attacker could possibly use this issue to
cause nginx to consume resources, resulting in a denial of service.
(CVE-2016-07
Red Hat
nginx: Insufficient limits of CNAME resolution in resolver
vendor_redhat·2016-01-26·CVSS 5.3
CVE-2016-0747 [MEDIUM] CWE-400 nginx: Insufficient limits of CNAME resolution in resolver
nginx: Insufficient limits of CNAME resolution in resolver
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
It was discovered that nginx did not limit recursion when resolving CNAME DNS records. An attacker able to manipulate DNS responses received by nginx could use this flaw to cause a worker process to use an excessive amount of resources if nginx enabled the resolver in its configuration.
Package: nginx16-nginx (Red Hat Software Collections) - Will not fix
Debian
CVE-2016-0747: nginx - The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly lim...
vendor_debian·2016·CVSS 5.3
CVE-2016-0747 [MEDIUM] CVE-2016-0747: nginx - The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly lim...
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
Scope: local
bookworm: resolved (fixed in 1.9.10-1)
bullseye: resolved (fixed in 1.9.10-1)
forky: resolved (fixed in 1.9.10-1)
sid: resolved (fixed in 1.9.10-1)
trixie: resolved (fixed in 1.9.10-1)
GHSA
GHSA-769v-gfhq-g2w7: The resolver in nginx before 1
ghsa_unreviewed·2022-05-13
CVE-2016-0747 [MEDIUM] CWE-400 GHSA-769v-gfhq-g2w7: The resolver in nginx before 1
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
OSV
CVE-2016-0747: The resolver in nginx before 1
osv·2016-02-15·CVSS 5.3
CVE-2016-0747 [MEDIUM] CVE-2016-0747: The resolver in nginx before 1
The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 does not properly limit CNAME resolution, which allows remote attackers to cause a denial of service (worker process resource consumption) via vectors related to arbitrary name resolution.
OSV
nginx vulnerabilities
osv·2016-02-09·CVSS 7.5
CVE-2016-0742 [HIGH] nginx vulnerabilities
nginx vulnerabilities
It was discovered that nginx incorrectly handled certain DNS server
responses when the resolver is enabled. A remote attacker could possibly
use this issue to cause nginx to crash, resulting in a denial of service.
(CVE-2016-0742)
It was discovered that nginx incorrectly handled CNAME response processing
when the resolver is enabled. A remote attacker could use this issue to
cause nginx to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2016-0746)
It was discovered that nginx incorrectly handled CNAME resolution when
the resolver is enabled. A remote attacker could possibly use this issue to
cause nginx to consume resources, resulting in a denial of service.
(CVE-2016-0747)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0747 nginx: Insufficient limits of CNAME resolution in resolver
bugzilla·2016-01-28·CVSS 5.3
CVE-2016-0747 [MEDIUM] CVE-2016-0747 nginx: Insufficient limits of CNAME resolution in resolver
CVE-2016-0747 nginx: Insufficient limits of CNAME resolution in resolver
The following flaw was found in the nginx resolver:
CNAME resolution was insufficiently limited, allowing an attacker who is able to trigger arbitrary name resolution to cause excessive resource consumption in worker processes.
This issue affects nginx only if the "resolver" directive is used in a configuration file.
The problems are fixed in nginx upstream versions 1.9.10 and 1.8.1.
External References:
http://mailman.nginx.org/pipermail/nginx-announce/2016/000169.html
Discussion:
Created nginx tracking bugs for this issue:
Affects: fedora-all [bug 1302592]
---
Upstream commit:
https://trac.nginx.org/nginx/changeset/93d70d87914c350948ab701cc99569680320e198/nginx
---
The nginx' DNS resolver is not enable
Bugzilla
CVE-2016-0742 CVE-2016-0746 CVE-2016-0747 nginx: various flaws [fedora-all]
bugzilla·2016-01-28·CVSS 7.5
CVE-2016-0742 [HIGH] CVE-2016-0742 CVE-2016-0746 CVE-2016-0747 nginx: various flaws [fedora-all]
CVE-2016-0742 CVE-2016-0746 CVE-2016-0747 nginx: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fe
Bugzilla
nginx: update for CVE-2016-0742, CVE-2016-0746, CVE-2016-0747 [epel-5]
bugzilla·2016-01-28·CVSS 7.5
CVE-2016-0742 [HIGH] nginx: update for CVE-2016-0742, CVE-2016-0746, CVE-2016-0747 [epel-5]
nginx: update for CVE-2016-0742, CVE-2016-0746, CVE-2016-0747 [epel-5]
Description of problem:
Current version of Nginx 0.8.55 in EPEL 5 is out-dated and contains vulnerabilities.
See: http://nginx.org/en/security_advisories.html
Solution: rebase to Nginx 1.8.1.
Discussion:
https://lists.fedoraproject.org/archives/list/[email protected]/thread/VFCIBCTGIYMVJCCUE3ZQVAARVHUF3YPP/
---
I read up on the thread, are you still moving forward with the update to latest release path? (Which I support)
---
nginx-1.10.1-1.el5 has been submitted as an update to Fedora EPEL 5. https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-c03e77f531
---
nginx-1.10.1-1.el5 has been pushed to the Fedora EPEL 5 testing repository. If problems still persist, please make note of it in this bu
Bugzilla
nginx: update for CVE-2016-0742, CVE-2016-0746, CVE-2016-0747 [epel-7]
bugzilla·2016-01-27·CVSS 7.5
CVE-2016-0742 [HIGH] nginx: update for CVE-2016-0742, CVE-2016-0746, CVE-2016-0747 [epel-7]
nginx: update for CVE-2016-0742, CVE-2016-0746, CVE-2016-0747 [epel-7]
Description of problem:
Current version of Nginx 1.6.3 in EPEL is out-dated and contains vulnerabilities.
See: http://nginx.org/en/security_advisories.html
Solution: rebase to Nginx 1.8.1
Discussion:
I pushed nginx-1.6.3-8.el7 yesterday with fixes for these CVEs. Please give karma. The update hasn't actually hit updates-testing yet so you will need to download the builds from koji.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-f17c082f00
http://koji.fedoraproject.org/koji/buildinfo?buildID=713981
---
I think this one can be safely closed since nginx 1.10 has been in EPEL 7 since Sep 7, 2016:
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2016-b51787d61d
Bugzilla
nginx: update for CVE-2016-0742, CVE-2016-0746, CVE-2016-0747 [epel-6]
bugzilla·2016-01-27·CVSS 7.5
CVE-2016-0742 [HIGH] nginx: update for CVE-2016-0742, CVE-2016-0746, CVE-2016-0747 [epel-6]
nginx: update for CVE-2016-0742, CVE-2016-0746, CVE-2016-0747 [epel-6]
Description of problem:
Current version of Nginx 1.6.3 in EPEL6 is out-dated and contains vulnerabilities.
See: http://nginx.org/en/security_advisories.html
Solution: rebase to Nginx 1.8.1
Discussion:
Correction, I meant to say that the current version in EPEL6 is 1.0.15. I still think a rebase to 1.8 is useful to avoid the vulnerabilities.
---
This is a real problem that doesn't have a perfect solution. Unfortunately, packaging policy is rather strict for "stable" distributions like RHEL and Debian. Major version updates are strongly discouraged.
However, one might be justified in pushing a major version update if there are unfixed security issues that cannot be backported. Backporting the 6 commits that fix th
http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.htmlhttp://mailman.nginx.org/pipermail/nginx/2016-January/049700.htmlhttp://seclists.org/fulldisclosure/2021/Sep/36http://www.debian.org/security/2016/dsa-3473http://www.securitytracker.com/id/1034869http://www.ubuntu.com/usn/USN-2892-1https://access.redhat.com/errata/RHSA-2016:1425https://bto.bluecoat.com/security-advisory/sa115https://bugzilla.redhat.com/show_bug.cgi?id=1302589https://security.gentoo.org/glsa/201606-06https://support.apple.com/kb/HT212818http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.htmlhttp://mailman.nginx.org/pipermail/nginx/2016-January/049700.htmlhttp://seclists.org/fulldisclosure/2021/Sep/36http://www.debian.org/security/2016/dsa-3473http://www.securitytracker.com/id/1034869http://www.ubuntu.com/usn/USN-2892-1https://access.redhat.com/errata/RHSA-2016:1425https://bto.bluecoat.com/security-advisory/sa115https://bugzilla.redhat.com/show_bug.cgi?id=1302589https://security.gentoo.org/glsa/201606-06https://support.apple.com/kb/HT212818
2016-02-15
Published