CVE-2016-0746
15.02.2016, 19:59
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.Enginsight
| Vendor | Product | Version |
|---|---|---|
| f5 | nginx | 0.6.18 ≤ 𝑥 ≤ 1.8.0 |
| f5 | nginx | 1.9.0 ≤ 𝑥 < 1.9.10 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.10 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| opensuse | leap | 42.1 |
| apple | xcode | 𝑥 < 13.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References