First published: Thu Jan 28 2016(Updated: )
IDE Xcode Server. Multiple issues were addressed by updating nginx to version 1.21.0.
Credit: CVE-2016-0742 CVE-2016-0746 CVE-2016-0747 CVE-2017-7529 CVE-2018-16843 CVE-2018-16844 CVE-2018-16845 CVE-2019-20372 secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/nginx | <1.9.10 | 1.9.10 |
redhat/nginx | <1.8.1 | 1.8.1 |
F5 Nginx | >=0.6.18<=1.8.0 | |
F5 Nginx | >=1.9.0<1.9.10 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =15.10 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
openSUSE Leap | =42.1 | |
Apple Xcode | <13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2016-0746 is a use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10.
CVE-2016-0746 does not directly affect Xcode Server, but updating nginx to version 1.21.0 will address the vulnerability.
CVE-2016-0746 has a severity rating of 9.8 (Critical).
To fix CVE-2016-0746, update nginx to version 1.21.0 or later.
You can find more information about CVE-2016-0746 at the following references: [1](https://support.apple.com/en-us/HT212818), [2](http://mailman.nginx.org/pipermail/nginx-announce/2016/000169.html), [3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1302592).