Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 8: MGASA-2022-0398 Critical: Nginx Memory Threats

mageia
Calendar Grey October 28, 2022
Dist Mageia Esm H88
The recent update of nginx in Mageia tackles significant vulnerabilities which could lead to system failures or the leakage of sensitive information. Ensure your systems are protected!
Two security issues were identified in the ngx_http_mp4_module, which might allow an attacker to cause a worker process crash or worker process memory disclosure by using a special...

Summary

Two security issues were identified in the ngx_http_mp4_module, which might allow an attacker to cause a worker process crash or worker process memory disclosure by using a specially crafted mp4 file, or might have potential other impact. (CVE-2022-41741, CVE-2022-41742)

References

- https://bugs.mageia.org/show_bug.cgi?id=30993

- https://mailman.nginx.org/pipermail/nginx-announce/2022/RBRRON6PYBJJM2XIAPQBFBVLR4Q6IHRA.html

- https://www.cve.org/CVERecord?id=CVE-2022-41741

- https://www.cve.org/CVERecord?id=CVE-2022-41742

Resolution

SRPMS

- 8/core/nginx-1.18.0-5.3.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 28 Oct 2022
URL: https://advisories.mageia.org/MGASA-2022-0398.html
Type: security
CVE: CVE-2022-41741, CVE-2022-41742

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here