QID 730096

Date Published: 2021-06-09

QID 730096: Nginx Arbitrary Code Execution Vulnerability

nginx [engine x] is an HTTP and reverse proxy server, a mail proxy server, and a generic TCP/UDP proxy server.

A security issue in nginx resolver was identified, which might allow an attacker to cause 1-byte memory overwrite by using a specially crafted DNS response

Affected Versions:
NGINX version from 0.6.18 to 1.20.0

QID Detection Logic (Unauthenticated):
The unauthenticated check tries to fetch the version from the version exposed in the Server: tag of a HTTP response.

Successful exploitation may lead to arbitrary code execution.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to install nginx 1.21.0, 1.20.1 to remediate this vulnerability.
    Vendor References

    CVEs related to QID 730096

    Software Advisories
    Advisory ID Software Component Link
    Nginx URL Logo nginx.org/en/security_advisories.html