CVE-2016-0742 describes a denial-of-service vulnerability in the NGINX resolver, affecting versions prior to 1.8.1 and 1.9.10, as well as various distributions including Apple, Canonical, Debian, F5, openSUSE, and Red Hat. This high-severity flaw (CVSS 7.5) allows remote attackers to crash worker processes via a crafted UDP DNS response, stemming from an invalid pointer dereference. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high EPSS and FAUCET Risk Score indicate a significant potential impact if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.6.18, < 1.8.1CPE matchmatch criteria | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* | ||
>= 1.9.0, < 1.9.10CPE matchmatch criteria | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* | ||
15.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
nginx: invalid pointer dereference in resolver
Jan 26, 2016Invalid pointer dereference in resolver
Jan 1, 2016Invalid pointer dereference in resolver
Jan 1, 2016Invalid pointer dereference in resolver
Jan 1, 2016Invalid pointer dereference in resolver
Jan 1, 2016Invalid pointer dereference in resolver
Jan 1, 2016Invalid pointer dereference in resolver
Invalid pointer dereference in resolver
Invalid pointer dereference in resolver