Back
CVE-2016-0746
CRITICAL
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.
Published: Feb 15, 2016
Modified: May 6, 2026
CWE-416
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (9)
| Vendor | Product | Version |
|---|---|---|
| f5 | nginx | * ≥ 0.6.18 |
| f5 | nginx | * ≥ 1.9.0 < 1.9.10 |
| canonical | ubuntu_linux | 14.04 |
| canonical | ubuntu_linux | 15.10 |
| debian | debian_linux | 7.0 |
| debian | debian_linux | 8.0 |
| debian | debian_linux | 9.0 |
| opensuse | leap | 42.1 |
| apple | xcode | * < 13.0 |
GitHub Security Advisory GHSA-c3r2-x25x-6jwc
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9...
References (22)
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html Mailing List, Third Party Advisory
- http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html Vendor Advisory
- http://seclists.org/fulldisclosure/2021/Sep/36 Mailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3473 Third Party Advisory
- http://www.securitytracker.com/id/1034869 Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2892-1 Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1425 Third Party Advisory
- https://bto.bluecoat.com/security-advisory/sa115 Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1302588 Issue Tracking, Patch, Third Party Advisory
- https://security.gentoo.org/glsa/201606-06 Third Party Advisory
- https://support.apple.com/kb/HT212818 Third Party Advisory
- http://lists.opensuse.org/opensuse-updates/2016-02/msg00042.html Mailing List, Third Party Advisory
- http://mailman.nginx.org/pipermail/nginx/2016-January/049700.html Vendor Advisory
- http://seclists.org/fulldisclosure/2021/Sep/36 Mailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3473 Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
6.34%
Top 9% most likely to be exploited
Threat Score
41.1 / 100
Data Sources
NVD
EPSS
GitHub