cbcvebase.
CVE-2021-23017
published 2021-06-01

CVE-2021-23017: A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory…

high7.7CVSS 3.1
AVNACHPRNUINSUCHIHAL
EXPLOIT
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debiannginx< nginx 1.18.0-6.1 (bookworm)nginx 1.18.0-6.1 (bookworm)
f5nginx
f5nginx>= 0 < 1.18.0-6.11.18.0-6.1
f5nginx>= 0 < 1.18.0-6.11.18.0-6.1
f5nginx>= 0 < 1.18.0-6.11.18.0-6.1
f5nginx>= 0 < 1.18.0-6.11.18.0-6.1
f5nginx>= 0.6.18 < 1.20.11.20.1
fedoraprojectfedora
fedoraprojectfedora
msrccm1_nginx_1.20.1-1_on_cbl_mariner_1.0
openrestyopenresty< 1.19.3.21.19.3.2
oracleblockchain_platform< 21.1.221.1.2
oraclecommunications_control_plane_monitor
oraclecommunications_control_plane_monitor
oraclecommunications_control_plane_monitor
oraclecommunications_control_plane_monitor
oraclecommunications_fraud_monitor3.4 – 4.4
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
oraclecommunications_operations_monitor
oraclecommunications_session_border_controller
oraclecommunications_session_border_controller
oracleenterprise_communications_broker
oracleenterprise_session_border_controller

CVSS provenance

nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
osv7.7HIGH