ALT-BU-2018-3642-1
Branch c7.1 update bulletin.
Closed vulnerabilities
BDU:2019-00982
Уязвимость реализации протокола HTTP/2 сервера nginx, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-00983
Уязвимость реализации протокола HTTP/2 сервера nginx, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2019-00984
Уязвимость модуля ngx_http_mp4_module сервера nginx, позволяющая нарушителю вызвать отказ в обслуживании или раскрыть защищаемую информацию
BDU:2021-04615
Уязвимость модуля autoindex сервера NGINX, связанная с целочисленным переполнением, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2017-20005
NGINX before 1.13.6 has a buffer overflow for years that exceed four digits, as demonstrated by a file with a modification date in 1969 that causes an integer overflow (or a false modification date far in the future), when encountered by the autoindex module.
- http://nginx.org/en/CHANGES
- http://nginx.org/en/CHANGES
- https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccf
- https://github.com/nginx/nginx/commit/0206ebe76f748bb39d9de4dd4b3fce777fdfdccf
- https://github.com/nginx/nginx/commit/b900cc28fcbb4cf5a32ab62f80b59292e1c85b4b
- https://github.com/nginx/nginx/commit/b900cc28fcbb4cf5a32ab62f80b59292e1c85b4b
- [debian-lts-announce] 20210607 [SECURITY] [DLA 2680-1] nginx security update
- [debian-lts-announce] 20210607 [SECURITY] [DLA 2680-1] nginx security update
- https://security.netapp.com/advisory/ntap-20210805-0006/
- https://security.netapp.com/advisory/ntap-20210805-0006/
- https://trac.nginx.org/nginx/ticket/1368
- https://trac.nginx.org/nginx/ticket/1368
Modified: 2024-11-21
CVE-2017-7529
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive information triggered by specially crafted request.
- [nginx-announce] 20170711 nginx security advisory (CVE-2017-7529)
- [nginx-announce] 20170711 nginx security advisory (CVE-2017-7529)
- 20210921 APPLE-SA-2021-09-20-4 Xcode 13
- 20210921 APPLE-SA-2021-09-20-4 Xcode 13
- 99534
- 99534
- 1039238
- 1039238
- RHSA-2017:2538
- RHSA-2017:2538
- https://puppet.com/security/cve/cve-2017-7529
- https://puppet.com/security/cve/cve-2017-7529
- https://support.apple.com/kb/HT212818
- https://support.apple.com/kb/HT212818
Modified: 2024-11-21
CVE-2018-16843
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
- openSUSE-SU-2019:2120
- openSUSE-SU-2019:2120
- http://mailman.nginx.org/pipermail/nginx-announce/2018/000220.html
- http://mailman.nginx.org/pipermail/nginx-announce/2018/000220.html
- 20210921 APPLE-SA-2021-09-20-4 Xcode 13
- 20210921 APPLE-SA-2021-09-20-4 Xcode 13
- 105868
- 105868
- 1042038
- 1042038
- RHSA-2018:3653
- RHSA-2018:3653
- RHSA-2018:3680
- RHSA-2018:3680
- RHSA-2018:3681
- RHSA-2018:3681
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16843
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16843
- https://support.apple.com/kb/HT212818
- https://support.apple.com/kb/HT212818
- USN-3812-1
- USN-3812-1
- DSA-4335
- DSA-4335
Modified: 2024-11-21
CVE-2018-16844
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
- openSUSE-SU-2019:2120
- openSUSE-SU-2019:2120
- http://mailman.nginx.org/pipermail/nginx-announce/2018/000220.html
- http://mailman.nginx.org/pipermail/nginx-announce/2018/000220.html
- 20210921 APPLE-SA-2021-09-20-4 Xcode 13
- 20210921 APPLE-SA-2021-09-20-4 Xcode 13
- 105868
- 105868
- 1042038
- 1042038
- RHSA-2018:3680
- RHSA-2018:3680
- RHSA-2018:3681
- RHSA-2018:3681
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16844
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16844
- https://support.apple.com/kb/HT212818
- https://support.apple.com/kb/HT212818
- USN-3812-1
- USN-3812-1
- DSA-4335
- DSA-4335
Modified: 2024-11-21
CVE-2018-16845
nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.
- openSUSE-SU-2019:2120
- openSUSE-SU-2019:2120
- http://mailman.nginx.org/pipermail/nginx-announce/2018/000221.html
- http://mailman.nginx.org/pipermail/nginx-announce/2018/000221.html
- 20210921 APPLE-SA-2021-09-20-4 Xcode 13
- 20210921 APPLE-SA-2021-09-20-4 Xcode 13
- 105868
- 105868
- 1042039
- 1042039
- RHSA-2018:3652
- RHSA-2018:3652
- RHSA-2018:3653
- RHSA-2018:3653
- RHSA-2018:3680
- RHSA-2018:3680
- RHSA-2018:3681
- RHSA-2018:3681
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16845
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16845
- [debian-lts-announce] 20181108 [SECURITY] [DLA 1572-1] nginx security update
- [debian-lts-announce] 20181108 [SECURITY] [DLA 1572-1] nginx security update
- https://support.apple.com/kb/HT212818
- https://support.apple.com/kb/HT212818
- USN-3812-1
- USN-3812-1
- DSA-4335
- DSA-4335