Description
When the ngx_mail_auth_http_module module is enabled on NGINX Plus or NGINX Open Source, undisclosed requests can cause worker processes to terminate. This issue may occur when (1) CRAM-MD5 or APOP authentication is enabled, and (2) the authentication server permits retry by returning the Auth-Wait response header. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Problem types
CWE-476 NULL Pointer Dereference
Product status
1.29.0 (semver) before 1.29.7
0.5.15 (semver) before 1.28.3
R36 (custom) before R36 P3
R35 (custom) before R35 P2
R34 (custom) before *
R33 (custom) before *
R32 (custom) before R32 P5
Credits
F5 acknowledges Arkadi Vainbrand for bringing this issue to our attention and following the highest standards of coordinated disclosure.
References
my.f5.com/manage/s/article/K000160383