nginx-1.21.0

2021-05-25 Thread Maxim Dounin
Changes with nginx 1.21.025 May 2021 *) Security: 1-byte memory overwrite might occur during DNS server response processing if the "resolver" directive was used, allowing an attacker who is able to forge UDP packets from the DNS server to

nginx-1.20.1

2021-05-25 Thread Maxim Dounin
Changes with nginx 1.20.125 May 2021 *) Security: 1-byte memory overwrite might occur during DNS server response processing if the "resolver" directive was used, allowing an attacker who is able to forge UDP packets from the DNS server to

nginx security advisory (CVE-2021-23017)

2021-05-25 Thread Maxim Dounin
Hello! A security issue in nginx resolver was identified, which might allow an attacker to cause 1-byte memory overwrite by using a specially crafted DNS response, resulting in worker process crash or, potentially, in arbitrary code execution (CVE-2021-23017). The issue only affects nginx if the

Re: nginx Digest, Vol 139, Issue 21

2021-05-25 Thread Amila Gunathilaka
Dear Francis, I'm sorry for taking time to reply to this, you were so keen about my problem. Thank you. Actually my problem was when sending *response *to the load balancer from the nginx ( not the request, it should be corrected as the *response *in my previous email). Such as my external load