CVE-2016-0746: Use After Free
IDE Xcode Server. Multiple issues were addressed by updating nginx to version 1.21.0.
Other sources
The following flaw was found in the nginx resolver:
Use-after-free condition might occur during CNAME response processing. This problem allows an attacker who is able to trigger name resolution to cause worker process crash, or might have potential other impact.
This issue affects nginx only if the "resolver" directive is used in a configuration file.
The problems are fixed in nginx upstream versions 1.9.10 and 1.8.1.
External References:
http://mailman.nginx.org/pipermail/nginx-announce/2016/000169.html
— Red Hat
Use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10 allows remote attackers to cause a denial of service (worker process crash) or possibly have unspecified other impact via a crafted DNS response related to CNAME response processing.
— MITRE
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2016-0746?
CVE-2016-0746 is a use-after-free vulnerability in the resolver in nginx 0.6.18 through 1.8.0 and 1.9.x before 1.9.10.
How does CVE-2016-0746 affect Xcode Server?
CVE-2016-0746 does not directly affect Xcode Server, but updating nginx to version 1.21.0 will address the vulnerability.
What is the severity of CVE-2016-0746?
CVE-2016-0746 has a severity rating of 9.8 (Critical).
How can I fix CVE-2016-0746?
To fix CVE-2016-0746, update nginx to version 1.21.0 or later.
Where can I find more information about CVE-2016-0746?
You can find more information about CVE-2016-0746 at the following references: [1](https://support.apple.com/en-us/HT212818), [2](http://mailman.nginx.org/pipermail/nginx-announce/2016/000169.html), [3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1302592).