ZeroHour

CVE-2021-23017

CVSS 3.1
7.7 high
EPSS
53%p99
Published
()
Modified
Description

A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

Vendors
f5openrestyfedoraprojectnetapporacle
Products
nginx, openresty, fedora, ontap select deploy administration utility, blockchain platform, communications control plane monitor, communications fraud monitor, communications operations monitor, communications session border controller, enterprise communications broker, enterprise session border controller, enterprise telephony fraud monitor
Weakness
CWE-193
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

In the news