USN-3812-1: nginx vulnerabilities

USN-3812-1: nginx vulnerabilities

nginx vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 18.10
  • Ubuntu 18.04 LTS
  • Ubuntu 16.04 LTS
  • Ubuntu 14.04 LTS

Summary

Several security issues were fixed in nginx.

Software Description

  • nginx – small, powerful, scalable web/proxy server

Details

It was discovered that nginx incorrectly handled the HTTP/2 implementation.
A remote attacker could possibly use this issue to cause excessive memory
consumption, leading to a denial of service. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16843)

Gal Goldshtein discovered that nginx incorrectly handled the HTTP/2
implementation. A remote attacker could possibly use this issue to cause
excessive CPU usage, leading to a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10.
(CVE-2018-16844)

It was discovered that nginx incorrectly handled the ngx_http_mp4_module
module. A remote attacker could possibly use this issue with a specially
crafted mp4 file to cause nginx to crash, stop responding, or access
arbitrary memory. (CVE-2018-16845)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 18.10
nginx-common1.15.5-0ubuntu2.1
nginx-core1.15.5-0ubuntu2.1
nginx-extras1.15.5-0ubuntu2.1
nginx-full1.15.5-0ubuntu2.1
nginx-light1.15.5-0ubuntu2.1
Ubuntu 18.04 LTS
nginx-common1.14.0-0ubuntu1.2
nginx-core1.14.0-0ubuntu1.2
nginx-extras1.14.0-0ubuntu1.2
nginx-full1.14.0-0ubuntu1.2
nginx-light1.14.0-0ubuntu1.2
Ubuntu 16.04 LTS
nginx-common1.10.3-0ubuntu0.16.04.3
nginx-core1.10.3-0ubuntu0.16.04.3
nginx-extras1.10.3-0ubuntu0.16.04.3
nginx-full1.10.3-0ubuntu0.16.04.3
nginx-light1.10.3-0ubuntu0.16.04.3
Ubuntu 14.04 LTS
nginx-common1.4.6-1ubuntu3.9
nginx-core1.4.6-1ubuntu3.9
nginx-extras1.4.6-1ubuntu3.9
nginx-full1.4.6-1ubuntu3.9
nginx-light1.4.6-1ubuntu3.9

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

Source: USN-3812-1: nginx vulnerabilities

About KENNETH 19688 Articles
지락문화예술공작단

Be the first to comment

Leave a Reply

Your email address will not be published.


*


이 사이트는 스팸을 줄이는 아키스밋을 사용합니다. 댓글이 어떻게 처리되는지 알아보십시오.