MGASA-2018-0459
Dashboard / Vulnerabilities / MGASA-2018-0459
MGASA-2018-0459
Summary: Updated nginx package fixes security vulnerabilities
Details: nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption (CVE-2018-16843). nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage (CVE-2018-16844). nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file (CVE-2018-16845).
References: https://advisories.mageia.org/MGASA-2018-0459.html, https://bugs.mageia.org/show_bug.cgi?id=23821
Affected packages
Package
Name: nginx
Purl: pkg:rpm/mageia/nginx?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
