CVE-2021-23017
01.06.2021, 13:15
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.Enginsight
| Vendor | Product | Version |
|---|---|---|
| f5 | nginx | 0.6.18 ≤ 𝑥 < 1.20.1 |
| openresty | openresty | 𝑥 < 1.19.3.2 |
| netapp | ontap_select_deploy_administration_utility | - |
| oracle | blockchain_platform | 𝑥 < 21.1.2 |
| oracle | communications_control_plane_monitor | 3.4 |
| oracle | communications_control_plane_monitor | 4.2 |
| oracle | communications_control_plane_monitor | 4.3 |
| oracle | communications_control_plane_monitor | 4.4 |
| oracle | communications_fraud_monitor | 3.4 ≤ 𝑥 ≤ 4.4 |
| oracle | communications_operations_monitor | 3.4 |
| oracle | communications_operations_monitor | 4.2 |
| oracle | communications_operations_monitor | 4.3 |
| oracle | communications_operations_monitor | 4.4 |
| oracle | communications_session_border_controller | 8.4 |
| oracle | communications_session_border_controller | 9.0 |
| oracle | enterprise_communications_broker | 3.3.0 |
| oracle | enterprise_session_border_controller | 8.4 |
| oracle | enterprise_session_border_controller | 9.0 |
| oracle | enterprise_telephony_fraud_monitor | 3.4 |
| oracle | enterprise_telephony_fraud_monitor | 4.2 |
| oracle | enterprise_telephony_fraud_monitor | 4.3 |
| oracle | enterprise_telephony_fraud_monitor | 4.4 |
| oracle | goldengate | 𝑥 < 21.4.0.0.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| nginx |
|
Common Weakness Enumeration
References