CVE-2021-23017
Nginx 1.20.0 - Denial of Service (DOS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
Se identificó un problema de seguridad en el solucionador de nginx, que podría permitir a un atacante que pueda falsificar paquetes UDP desde el servidor DNS para causar una sobrescritura de memoria de 1 byte, lo que causaría un bloqueo del proceso de trabajo u otro impacto potencial
A flaw was found in nginx. An off-by-one error while processing DNS responses allows a network attacker to write a dot character out of bounds in a heap allocated buffer which can allow overwriting the least significant byte of next heap chunk metadata likely leading to a remote code execution in certain circumstances. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Nginx version 1.20.0 suffers from a denial of service vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-06 CVE Reserved
- 2021-05-26 CVE Published
- 2022-07-11 First Exploit
- 2024-08-03 CVE Updated
- 2024-11-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-193: Off-by-one Error
CAPEC
References (20)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/50973 | 2022-07-11 | |
https://github.com/M507/CVE-2021-23017-PoC | 2023-11-12 | |
https://github.com/ShivamDey/CVE-2021-23017 | 2023-10-21 | |
https://github.com/lakshit1212/CVE-2021-23017-PoC | 2023-07-20 |
URL | Date | SRC |
---|---|---|
http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpuapr2022.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpujan2022.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpuoct2021.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
F5 Search vendor "F5" | Nginx Search vendor "F5" for product "Nginx" | >= 0.6.18 < 1.20.1 Search vendor "F5" for product "Nginx" and version " >= 0.6.18 < 1.20.1" | - |
Affected
| ||||||
Openresty Search vendor "Openresty" | Openresty Search vendor "Openresty" for product "Openresty" | < 1.19.3.2 Search vendor "Openresty" for product "Openresty" and version " < 1.19.3.2" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 33 Search vendor "Fedoraproject" for product "Fedora" and version "33" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Ontap Select Deploy Administration Utility Search vendor "Netapp" for product "Ontap Select Deploy Administration Utility" | - | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Blockchain Platform Search vendor "Oracle" for product "Blockchain Platform" | < 21.1.2 Search vendor "Oracle" for product "Blockchain Platform" and version " < 21.1.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Control Plane Monitor Search vendor "Oracle" for product "Communications Control Plane Monitor" | 3.4 Search vendor "Oracle" for product "Communications Control Plane Monitor" and version "3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Control Plane Monitor Search vendor "Oracle" for product "Communications Control Plane Monitor" | 4.2 Search vendor "Oracle" for product "Communications Control Plane Monitor" and version "4.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Control Plane Monitor Search vendor "Oracle" for product "Communications Control Plane Monitor" | 4.3 Search vendor "Oracle" for product "Communications Control Plane Monitor" and version "4.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Control Plane Monitor Search vendor "Oracle" for product "Communications Control Plane Monitor" | 4.4 Search vendor "Oracle" for product "Communications Control Plane Monitor" and version "4.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Fraud Monitor Search vendor "Oracle" for product "Communications Fraud Monitor" | >= 3.4 <= 4.4 Search vendor "Oracle" for product "Communications Fraud Monitor" and version " >= 3.4 <= 4.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Operations Monitor Search vendor "Oracle" for product "Communications Operations Monitor" | 3.4 Search vendor "Oracle" for product "Communications Operations Monitor" and version "3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Operations Monitor Search vendor "Oracle" for product "Communications Operations Monitor" | 4.2 Search vendor "Oracle" for product "Communications Operations Monitor" and version "4.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Operations Monitor Search vendor "Oracle" for product "Communications Operations Monitor" | 4.3 Search vendor "Oracle" for product "Communications Operations Monitor" and version "4.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Operations Monitor Search vendor "Oracle" for product "Communications Operations Monitor" | 4.4 Search vendor "Oracle" for product "Communications Operations Monitor" and version "4.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Session Border Controller Search vendor "Oracle" for product "Communications Session Border Controller" | 8.4 Search vendor "Oracle" for product "Communications Session Border Controller" and version "8.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Session Border Controller Search vendor "Oracle" for product "Communications Session Border Controller" | 9.0 Search vendor "Oracle" for product "Communications Session Border Controller" and version "9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Communications Broker Search vendor "Oracle" for product "Enterprise Communications Broker" | 3.3.0 Search vendor "Oracle" for product "Enterprise Communications Broker" and version "3.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Session Border Controller Search vendor "Oracle" for product "Enterprise Session Border Controller" | 8.4 Search vendor "Oracle" for product "Enterprise Session Border Controller" and version "8.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Session Border Controller Search vendor "Oracle" for product "Enterprise Session Border Controller" | 9.0 Search vendor "Oracle" for product "Enterprise Session Border Controller" and version "9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Telephony Fraud Monitor Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" | 3.4 Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" and version "3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Telephony Fraud Monitor Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" | 4.2 Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" and version "4.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Telephony Fraud Monitor Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" | 4.3 Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" and version "4.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Telephony Fraud Monitor Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" | 4.4 Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" and version "4.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate Search vendor "Oracle" for product "Goldengate" | < 21.4.0.0.0 Search vendor "Oracle" for product "Goldengate" and version " < 21.4.0.0.0" | - |
Affected
|