imPC@ndo IT

Tracker / CVE-2021-23017

CVE-2021-23017

High 7.7

A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

Affected products and versions

f5 nginx · 0.6.18 → 1.20.1
fedoraproject fedora
netapp ontap_select_deploy_administration_utility
openresty openresty · … → 1.19.3.2
oracle blockchain_platform · … → 21.1.2
oracle communications_control_plane_monitor
oracle communications_fraud_monitor · 3.4 → 4.4
oracle communications_operations_monitor
oracle communications_session_border_controller
oracle enterprise_communications_broker
oracle enterprise_session_border_controller
oracle enterprise_telephony_fraud_monitor
oracle goldengate · … → 21.4.0.0.0

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References