CVE-2021-23017
A flaw was found in nginx. An off-by-one error while processing DNS responses allows a network attacker to write a dot character out of bounds in a heap allocated buffer which can allow overwriting the least significant byte of next heap chunk metadata likely leading to a remote code execution in certain circumstances. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue in nginx resolver?
The vulnerability ID for this security issue in nginx resolver is CVE-2021-23017.
What is the severity of CVE-2021-23017?
The severity of CVE-2021-23017 is high with a CVSS score of 8.1.
How does the vulnerability in nginx resolver occur?
The vulnerability in nginx resolver is caused by an off-by-one error while processing DNS responses.
What is the potential impact of this vulnerability?
The potential impact of this vulnerability is remote code execution.
How can I fix the vulnerability in nginx resolver?
To fix the vulnerability in nginx resolver, update to version 1.21.0 or 1.20.1 of nginx.