之前有过一个 nginx resolver 拒绝服务漏洞(CVE-2016-0742),现在又出了一个.如果没用resolver 参数,那没影响,可以升到最新nginx-1.21.0来解决.Changes with nginx 1.21.0 25 May 2021
*) Security: 1-byte memory overwrite might occur during DNS server
response processing if the "resolver" directive was used, allowing an
attacker who is able to forge UDP packets from the DNS server to
cause worker process crash or, potentially, arbitrary code execution
(CVE-2021-23017).概述ngx_resolver_copy()在处理DNS响应时出现一个off-by-one错误,利用该漏洞网络攻击者可以在堆分配的缓冲区中写一个点字符(.’, 0x2E)导致超出范围。 所有配置解析器语法的(reso
...
继续阅读
(94)