Site icon 지락문화예술공작단

USN-3812-1: nginx vulnerabilities

USN-3812-1: nginx vulnerabilities

nginx vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

Summary

Several security issues were fixed in nginx.

Software Description

Details

It was discovered that nginx incorrectly handled the HTTP/2 implementation.
A remote attacker could possibly use this issue to cause excessive memory
consumption, leading to a denial of service. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16843)

Gal Goldshtein discovered that nginx incorrectly handled the HTTP/2
implementation. A remote attacker could possibly use this issue to cause
excessive CPU usage, leading to a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10.
(CVE-2018-16844)

It was discovered that nginx incorrectly handled the ngx_http_mp4_module
module. A remote attacker could possibly use this issue with a specially
crafted mp4 file to cause nginx to crash, stop responding, or access
arbitrary memory. (CVE-2018-16845)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 18.10
nginx-common1.15.5-0ubuntu2.1
nginx-core1.15.5-0ubuntu2.1
nginx-extras1.15.5-0ubuntu2.1
nginx-full1.15.5-0ubuntu2.1
nginx-light1.15.5-0ubuntu2.1
Ubuntu 18.04 LTS
nginx-common1.14.0-0ubuntu1.2
nginx-core1.14.0-0ubuntu1.2
nginx-extras1.14.0-0ubuntu1.2
nginx-full1.14.0-0ubuntu1.2
nginx-light1.14.0-0ubuntu1.2
Ubuntu 16.04 LTS
nginx-common1.10.3-0ubuntu0.16.04.3
nginx-core1.10.3-0ubuntu0.16.04.3
nginx-extras1.10.3-0ubuntu0.16.04.3
nginx-full1.10.3-0ubuntu0.16.04.3
nginx-light1.10.3-0ubuntu0.16.04.3
Ubuntu 14.04 LTS
nginx-common1.4.6-1ubuntu3.9
nginx-core1.4.6-1ubuntu3.9
nginx-extras1.4.6-1ubuntu3.9
nginx-full1.4.6-1ubuntu3.9
nginx-light1.4.6-1ubuntu3.9

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

In general, a standard system update will make all the necessary changes.

References

Source: USN-3812-1: nginx vulnerabilities

Exit mobile version