MGASA-2019-0342 - Updated nginx packages fix security vulnerabilities

Publication date: 30 Nov 2019
URL: https://advisories.mageia.org/MGASA-2019-0342.html
Type: security
Affected Mageia releases: 7
CVE: CVE-2019-9511,
     CVE-2019-9513,
     CVE-2019-9516

Updated nginx packages fix security vulnerabilities:

When using HTTP/2 a client might cause excessive memory consumption and
CPU usage (CVE-2019-9511, CVE-2019-9513, CVE-2019-9516).

References:
- https://bugs.mageia.org/show_bug.cgi?id=25303
- https://nginx.org/en/CHANGES-1.16
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9511
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9513
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9516

SRPMS:
- 7/core/nginx-1.16.1-1.mga7

Mageia 2019-0342: nginx security update

Updated nginx packages fix security vulnerabilities: When using HTTP/2 a client might cause excessive memory consumption and CPU usage (CVE-2019-9511, CVE-2019-9513, CVE-2019-9516...

Summary

Updated nginx packages fix security vulnerabilities:
When using HTTP/2 a client might cause excessive memory consumption and CPU usage (CVE-2019-9511, CVE-2019-9513, CVE-2019-9516).

References

- https://bugs.mageia.org/show_bug.cgi?id=25303

- https://nginx.org/en/CHANGES-1.16

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9511

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9513

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9516

Resolution

MGASA-2019-0342 - Updated nginx packages fix security vulnerabilities

SRPMS

- 7/core/nginx-1.16.1-1.mga7

Severity
Publication date: 30 Nov 2019
URL: https://advisories.mageia.org/MGASA-2019-0342.html
Type: security
CVE: CVE-2019-9511, CVE-2019-9513, CVE-2019-9516

Related News