vulnerability

Ubuntu: USN-2892-1 (CVE-2016-0747): nginx vulnerabilities

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:P)
Published
Feb 9, 2016
Added
Feb 15, 2016
Modified
Apr 14, 2025

Description

It was discovered that nginx incorrectly handled certain DNS server
responses when the resolver is enabled. A remote attacker could possibly
use this issue to cause nginx to crash, resulting in a denial of service.
(CVE-2016-0742)

It was discovered that nginx incorrectly handled CNAME response processing
when the resolver is enabled. A remote attacker could use this issue to
cause nginx to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2016-0746)

It was discovered that nginx incorrectly handled CNAME resolution when
the resolver is enabled. A remote attacker could possibly use this issue to
cause nginx to consume resources, resulting in a denial of service.
(CVE-2016-0747)

Solution(s)

ubuntu-upgrade-nginx-coreubuntu-upgrade-nginx-extrasubuntu-upgrade-nginx-fullubuntu-upgrade-nginx-lightubuntu-upgrade-nginx-naxsi
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.