CVE-2011-4315: Buffer Overflow
Published Dec 8, 2011
·Updated
Heap-based buffer overflow in compression-pointer processing in core/ngxresolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
Affected Software
6 affected components
F5 Nginx>=0.6.18<1.0.10
F5 Nginx>=1.1.0<=1.1.7
Fedoraproject Fedora=16
SUSE Studio=1.2
SUSE Studio onsite=1.2
SUSE WebYaST=1.2
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 8, 2011
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2011-4315?
CVE-2011-4315 has a medium severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2011-4315?
To fix CVE-2011-4315, upgrade nginx to version 1.1.0 or later.
3
What systems are affected by CVE-2011-4315?
CVE-2011-4315 affects nginx versions before 1.0.10 and between 1.1.0 and 1.1.7, as well as certain Fedora and SUSE systems.
4
What type of vulnerability is CVE-2011-4315?
CVE-2011-4315 is a heap-based buffer overflow vulnerability.
5
Can CVE-2011-4315 be exploited remotely?
Yes, CVE-2011-4315 can be exploited remotely by sending a long response to a vulnerable nginx server.