PublicDateAtUSN: 2016-01-26 Candidate: CVE-2016-0742 PublicDate: 2016-02-15 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0742 http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html https://ubuntu.com/security/notices/USN-2892-1 Description: The resolver in nginx before 1.8.1 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (invalid pointer dereference and worker process crash) via a crafted UDP DNS response. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=812806 https://bugs.launchpad.net/ubuntu/+source/nginx/+bug/1538165 Priority: medium Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L [5.3 MEDIUM] Patches_nginx: upstream: https://github.com/nginx/nginx/commit/c44fd4e837f979912749a5a19490ccb9b46398d3 upstream_nginx: released (1.9.10-1, 1.9.10, 1.8.1) precise_nginx: ignored (reached end-of-life) precise/esm_nginx: DNE (precise was needed) trusty_nginx: released (1.4.6-1ubuntu3.4) trusty/esm_nginx: released (1.4.6-1ubuntu3.4) vivid_nginx: ignored (reached end-of-life) vivid/stable-phone-overlay_nginx: DNE vivid/ubuntu-core_nginx: DNE wily_nginx: released (1.9.3-1ubuntu1.1) xenial_nginx: released (1.9.10-0ubuntu1) esm-infra/xenial_nginx: released (1.9.10-0ubuntu1) yakkety_nginx: released (1.9.10-0ubuntu1) zesty_nginx: released (1.9.10-0ubuntu1) devel_nginx: released (1.9.10-0ubuntu1)