CVE-2021-23017 - log back

CVE-2021-23017 edited at 15 Jun 2021 09:13:56
Description
A security issue in nginx resolver was identified, which might allow an attacker to cause 1-byte memory overwrite by using a specially crafted DNS response, resulting in worker process crash or, potentially, in arbitrary code execution.
- The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is able to forge UDP packets from the DNS server.
+ The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is able to forge UDP packets from the DNS server.
CVE-2021-23017 edited at 31 May 2021 18:07:00
Description
A security issue in nginx resolver was identified, which might allow an attacker to cause 1-byte memory overwrite by using a specially crafted DNS response, resulting in worker process crash or, potentially, in arbitrary code execution.
+
The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is able to forge UDP packets from the DNS server.
References
+ https://www.x41-dsec.de/lab/advisories/x41-2021-002-nginx-resolver-copy/
+ https://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html
http://nginx.org/download/patch.2021.resolver.txt
+ https://github.com/nginx/nginx/commit/7199ebc203f74fd9e44595474de6bdc41740c5cf
CVE-2021-23017 edited at 25 May 2021 15:57:30
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ A security issue in nginx resolver was identified, which might allow an attacker to cause 1-byte memory overwrite by using a specially crafted DNS response, resulting in worker process crash or, potentially, in arbitrary code execution.
+ The issue only affects nginx if the "resolver" directive is used in the configuration file. Further, the attack is only possible if an attacker is able to forge UDP packets from the DNS server.
References
+ http://nginx.org/download/patch.2021.resolver.txt
Notes
CVE-2021-23017 created at 25 May 2021 15:56:29