MGASA-2022-0398 - Updated nginx packages fix security vulnerability

Publication date: 28 Oct 2022
URL: https://advisories.mageia.org/MGASA-2022-0398.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2022-41741,
     CVE-2022-41742

Two security issues were identified in the ngx_http_mp4_module, which
might allow an attacker to cause a worker process crash or worker
process memory disclosure by using a specially crafted mp4 file, or
might have potential other impact. (CVE-2022-41741, CVE-2022-41742)

References:
- https://bugs.mageia.org/show_bug.cgi?id=30993
- https://mailman.nginx.org/pipermail/nginx-announce/2022/RBRRON6PYBJJM2XIAPQBFBVLR4Q6IHRA.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41741
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41742

SRPMS:
- 8/core/nginx-1.18.0-5.3.mga8

Mageia 2022-0398: nginx security update

Two security issues were identified in the ngx_http_mp4_module, which might allow an attacker to cause a worker process crash or worker process memory disclosure by using a special...

Summary

Two security issues were identified in the ngx_http_mp4_module, which might allow an attacker to cause a worker process crash or worker process memory disclosure by using a specially crafted mp4 file, or might have potential other impact. (CVE-2022-41741, CVE-2022-41742)

References

- https://bugs.mageia.org/show_bug.cgi?id=30993

- https://mailman.nginx.org/pipermail/nginx-announce/2022/RBRRON6PYBJJM2XIAPQBFBVLR4Q6IHRA.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41741

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41742

Resolution

MGASA-2022-0398 - Updated nginx packages fix security vulnerability

SRPMS

- 8/core/nginx-1.18.0-5.3.mga8

Severity
Publication date: 28 Oct 2022
URL: https://advisories.mageia.org/MGASA-2022-0398.html
Type: security
CVE: CVE-2022-41741, CVE-2022-41742

Related News