CVE-2021-23017
Nginx 1.20.0 - Denial of Service (DOS)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
9Exploited in Wild
-Decision
Descriptions
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.
Se identificó un problema de seguridad en el solucionador de nginx, que podría permitir a un atacante que pueda falsificar paquetes UDP desde el servidor DNS para causar una sobrescritura de memoria de 1 byte, lo que causaría un bloqueo del proceso de trabajo u otro impacto potencial
A flaw was found in nginx. An off-by-one error while processing DNS responses allows a network attacker to write a dot character out of bounds in a heap allocated buffer which can allow overwriting the least significant byte of next heap chunk metadata likely leading to a remote code execution in certain circumstances. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Red Hat Advanced Cluster Management for Kubernetes 2.4.0 images Red Hat Advanced Cluster Management for Kubernetes provides the capabilities to address common challenges that administrators and site reliability engineers face as they work across a range of public and private cloud environments. Clusters and applications are all visible and managed from a single console—with security policy built in. This advisory contains the container images for Red Hat Advanced Cluster Management for Kubernetes, which fix several bugs and security issues. Issues addressed include buffer overflow, denial of service, information leakage, integer overflow, out of bounds read, and path sanitization vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-06 CVE Reserved
- 2021-05-26 CVE Published
- 2021-05-26 First Exploit
- 2024-08-03 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-193: Off-by-one Error
CAPEC
References (25)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/167720 | 2022-07-11 | |
https://packetstorm.news/files/id/162830 | 2021-05-26 | |
https://www.exploit-db.com/exploits/50973 | 2022-07-11 | |
https://github.com/M507/CVE-2021-23017-PoC | 2023-11-12 | |
https://github.com/ShivamDey/CVE-2021-23017 | 2023-10-21 | |
https://github.com/lakshit1212/CVE-2021-23017-PoC | 2023-07-20 | |
https://github.com/niandy/nginx-patch | 2021-12-22 | |
https://github.com/z3usx01/CVE-2021-23017-POC | 2024-12-08 | |
https://github.com/lukwagoasuman/-home-lukewago-Downloads-CVE-2021-23017-Nginx-1.14 | 2025-01-30 |
URL | Date | SRC |
---|---|---|
http://mailman.nginx.org/pipermail/nginx-announce/2021/000300.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpuapr2022.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpujan2022.html | 2023-11-07 | |
https://www.oracle.com/security-alerts/cpuoct2021.html | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
F5 Search vendor "F5" | Nginx Search vendor "F5" for product "Nginx" | >= 0.6.18 < 1.20.1 Search vendor "F5" for product "Nginx" and version " >= 0.6.18 < 1.20.1" | - |
Affected
| ||||||
Openresty Search vendor "Openresty" | Openresty Search vendor "Openresty" for product "Openresty" | < 1.19.3.2 Search vendor "Openresty" for product "Openresty" and version " < 1.19.3.2" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 33 Search vendor "Fedoraproject" for product "Fedora" and version "33" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Ontap Select Deploy Administration Utility Search vendor "Netapp" for product "Ontap Select Deploy Administration Utility" | - | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Blockchain Platform Search vendor "Oracle" for product "Blockchain Platform" | < 21.1.2 Search vendor "Oracle" for product "Blockchain Platform" and version " < 21.1.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Control Plane Monitor Search vendor "Oracle" for product "Communications Control Plane Monitor" | 3.4 Search vendor "Oracle" for product "Communications Control Plane Monitor" and version "3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Control Plane Monitor Search vendor "Oracle" for product "Communications Control Plane Monitor" | 4.2 Search vendor "Oracle" for product "Communications Control Plane Monitor" and version "4.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Control Plane Monitor Search vendor "Oracle" for product "Communications Control Plane Monitor" | 4.3 Search vendor "Oracle" for product "Communications Control Plane Monitor" and version "4.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Control Plane Monitor Search vendor "Oracle" for product "Communications Control Plane Monitor" | 4.4 Search vendor "Oracle" for product "Communications Control Plane Monitor" and version "4.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Fraud Monitor Search vendor "Oracle" for product "Communications Fraud Monitor" | >= 3.4 <= 4.4 Search vendor "Oracle" for product "Communications Fraud Monitor" and version " >= 3.4 <= 4.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Operations Monitor Search vendor "Oracle" for product "Communications Operations Monitor" | 3.4 Search vendor "Oracle" for product "Communications Operations Monitor" and version "3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Operations Monitor Search vendor "Oracle" for product "Communications Operations Monitor" | 4.2 Search vendor "Oracle" for product "Communications Operations Monitor" and version "4.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Operations Monitor Search vendor "Oracle" for product "Communications Operations Monitor" | 4.3 Search vendor "Oracle" for product "Communications Operations Monitor" and version "4.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Operations Monitor Search vendor "Oracle" for product "Communications Operations Monitor" | 4.4 Search vendor "Oracle" for product "Communications Operations Monitor" and version "4.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Session Border Controller Search vendor "Oracle" for product "Communications Session Border Controller" | 8.4 Search vendor "Oracle" for product "Communications Session Border Controller" and version "8.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Session Border Controller Search vendor "Oracle" for product "Communications Session Border Controller" | 9.0 Search vendor "Oracle" for product "Communications Session Border Controller" and version "9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Communications Broker Search vendor "Oracle" for product "Enterprise Communications Broker" | 3.3.0 Search vendor "Oracle" for product "Enterprise Communications Broker" and version "3.3.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Session Border Controller Search vendor "Oracle" for product "Enterprise Session Border Controller" | 8.4 Search vendor "Oracle" for product "Enterprise Session Border Controller" and version "8.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Session Border Controller Search vendor "Oracle" for product "Enterprise Session Border Controller" | 9.0 Search vendor "Oracle" for product "Enterprise Session Border Controller" and version "9.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Telephony Fraud Monitor Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" | 3.4 Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" and version "3.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Telephony Fraud Monitor Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" | 4.2 Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" and version "4.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Telephony Fraud Monitor Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" | 4.3 Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" and version "4.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Enterprise Telephony Fraud Monitor Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" | 4.4 Search vendor "Oracle" for product "Enterprise Telephony Fraud Monitor" and version "4.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Goldengate Search vendor "Oracle" for product "Goldengate" | < 21.4.0.0.0 Search vendor "Oracle" for product "Goldengate" and version " < 21.4.0.0.0" | - |
Affected
|