← All CVEs

CVE-2021-23017

high · 7.7

A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in worker process crash or potential other impact.

7.7
CVSS
53.5%
EPSS (exploit prob.)
99th
EPSS percentile
2021-06-01
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Weaknesses

CWE-193

Affected products

VendorProductAffected versions
f5nginx>= 0.6.18, < 1.20.1
openrestyopenresty< 1.19.3.2
fedoraprojectfedora33
fedoraprojectfedora34
netappontap_select_deploy_administration_utilityall versions
oracleblockchain_platform< 21.1.2
oraclecommunications_control_plane_monitor3.4
oraclecommunications_control_plane_monitor4.2
oraclecommunications_control_plane_monitor4.3
oraclecommunications_control_plane_monitor4.4
oraclecommunications_fraud_monitor>= 3.4, <= 4.4
oraclecommunications_operations_monitor3.4
oraclecommunications_operations_monitor4.2
oraclecommunications_operations_monitor4.3
oraclecommunications_operations_monitor4.4
oraclecommunications_session_border_controller8.4
oraclecommunications_session_border_controller9.0
oracleenterprise_communications_broker3.3.0
oracleenterprise_session_border_controller8.4
oracleenterprise_session_border_controller9.0
oracleenterprise_telephony_fraud_monitor3.4
oracleenterprise_telephony_fraud_monitor4.2
oracleenterprise_telephony_fraud_monitor4.3
oracleenterprise_telephony_fraud_monitor4.4
oraclegoldengate< 21.4.0.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-23017