SUSE-SU-2019:2309-1
Dashboard / Vulnerabilities / SUSE-SU-2019:2309-1
SUSE-SU-2019:2309-1
Summary: Security update for nginx
Details: This update for nginx fixes the following issues: Security issues fixed: - CVE-2019-9511: Fixed a denial of service by manipulating the window size and stream prioritization (bsc#1145579). - CVE-2019-9513: Fixed a denial of service caused by resource loops (bsc#1145580). - CVE-2019-9516: Fixed a denial of service caused by header leaks (bsc#1145582). - CVE-2018-16845: Fixed denial of service and memory disclosure via mp4 module (bsc#1115015). - CVE-2018-16843: Fixed excessive memory consumption in HTTP/2 implementation (bsc#1115022). - CVE-2018-16844: Fixed excessive CPU usage via flaw in HTTP/2 implementation (bsc#1115025).
References: https://www.suse.com/support/update/announcement/2019/suse-su-20192309-1/, https://bugzilla.suse.com/1115015, https://bugzilla.suse.com/1115022, https://bugzilla.suse.com/1115025, https://bugzilla.suse.com/1145579, https://bugzilla.suse.com/1145580, https://bugzilla.suse.com/1145582, https://www.suse.com/security/cve/CVE-2018-16843, https://www.suse.com/security/cve/CVE-2018-16844, https://www.suse.com/security/cve/CVE-2018-16845, https://www.suse.com/security/cve/CVE-2019-9511, https://www.suse.com/security/cve/CVE-2019-9513, https://www.suse.com/security/cve/CVE-2019-9516
Affected packages
Package
Name: nginx
Purl: pkg:rpm/suse/nginx&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP1
Affected ranges
Type: ECOSYSTEM
Events:
