[ASA-202106-36] nginx: arbitrary code execution
santiago at archlinux.org
Thu Jun 17 16:25:41 UTC 2021
Arch Linux Security Advisory ASA-202106-36
Date : 2021-06-15
CVE-ID : CVE-2021-23017
Package : nginx
Type : arbitrary code execution
Remote : Yes
Link : https://security.archlinux.org/AVG-1988
The package nginx before version 1.20.1-1 is vulnerable to arbitrary
Upgrade to 1.20.1-1.
# pacman -Syu "nginx>=1.20.1-1"
The problem has been fixed upstream in version 1.20.1.
The issue can be mitigated by removing the "resolver" directive from
the configuration file.
A security issue in nginx resolver was identified, which might allow an
attacker to cause 1-byte memory overwrite by using a specially crafted
DNS response, resulting in worker process crash or, potentially, in
arbitrary code execution.
The issue only affects nginx if the "resolver" directive is used in the
configuration file. Further, the attack is only possible if an attacker
is able to forge UDP packets from the DNS server.
A remote attacker could crash the nginx server, or potentially execute
arbitrary code, using a crafted DNS server response.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 833 bytes
Desc: not available
More information about the arch-security