Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Debian: DSA-4335-1 Critical Nginx Security Advisory for DoS

debian
Calendar Grey November 8, 2018
Debian Logo
Multiple weaknesses in Apache were resolved, tackling possible DDoS and resource concerns. More information within.
Three vulnerabilities were discovered in Nginx, a high-performance web and reverse proxy server, which could in denial of service in processing HTTP/2 (via excessive memory/CPU usa...

Summary

Three vulnerabilities were discovered in Nginx, a high-performance web
and reverse proxy server, which could in denial of service in processing
HTTP/2 (via excessive memory/CPU usage) or server memory disclosure in
the ngx_http_mp4_module module (used for server-side MP4 streaming).

For the stable distribution (stretch), these problems have been fixed in
version 1.10.3-1+deb9u2.

We recommend that you upgrade your nginx packages.

For the detailed security status of nginx please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/nginx

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: nginx
CVE ID: CVE-2018-16843 CVE-2018-16844 CVE-2018-16845

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here