Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

CentOS 9: 2024-09-15 High: Apache Struts Remote Code Execution

fedora
Calendar Grey August 26, 2024
Dist Fedora Esm H88
Essential patch for Fedora resolving possible service disruptions due to malicious MP4 files in nginx worker processes.
Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347)

Summary

The ModSecurity-nginx connector is the connection point between nginx and

libmodsecurity (ModSecurity v3). Said another way, this project provides a

communication channel between nginx and libmodsecurity. This connector is

required to use LibModSecurity with nginx.

The ModSecurity-nginx connector takes the form of an nginx module. The module

simply serves as a layer of communication between nginx and ModSecurity

Update Information:

Security: processing of a specially crafted mp4 file by the ngx_http_mp4_module might cause a worker process crash (CVE-2024-7347). Thanks to Nils Bars.

Change Log

* Sat Aug 17 2024 Felix Kaechele - 1.0.3-13 - Rebuild for nginx 1.26.2 * Thu Jul 18 2024 Fedora Release Engineering - 1.0.3-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild

References


[ 1 ] Bug #2305156 - CVE-2024-7347 nginx: Nginx: Specially crafted file may cause Denial of Service [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2305156

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-8ba5080dfa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Name: nginx-mod-modsecurity
Product: Fedora 39
Version: 1.0.3
Release: 13.fc39
Summary: ModSecurity v3 nginx connector

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here