CVE-2021-23017

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/06/2021
Last modified:
07/11/2023

Description

A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* 0.6.18 (including) 1.20.1 (excluding)
cpe:2.3:a:openresty:openresty:*:*:*:*:*:*:*:* 1.19.3.2 (excluding)
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:a:oracle:blockchain_platform:*:*:*:*:*:*:*:* 21.1.2 (excluding)
cpe:2.3:a:oracle:communications_control_plane_monitor:3.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_control_plane_monitor:4.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_control_plane_monitor:4.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_control_plane_monitor:4.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_fraud_monitor:*:*:*:*:*:*:*:* 3.4 (including) 4.4 (including)
cpe:2.3:a:oracle:communications_operations_monitor:3.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_operations_monitor:4.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_operations_monitor:4.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:communications_operations_monitor:4.4:*:*:*:*:*:*:*