This update for nginx to version 1.14.2 fixes the following issues: Security vulnerabilities addressed: - CVE-2018-16843 CVE-2018-16844: Fixed an issue whereby a client using HTTP/2 might cause excessive memory consumption and CPU usage (bsc#1115025 bsc#1115022). - CVE-2018-16845: Fixed an issue which might result in worker process memory disclosure whne processing of a specially crafted mp4 file with the ngx_http_mp4_module (bsc#1115015). Other bug fixes and changes made: - Fixed an issue with handling of client addresses when using unix domain listen sockets to work with datagrams on Linux. - The logging level of the "http request", "https proxy request", "unsupported protocol", "version too low", "no suitable key share", and "no suitable signature algorithm" SSL errors has been lowered from
#1115015 #1115022 #1115025
Cross- CVE-2018-16843 CVE-2018-16844 CVE-2018-16845
Affected Products:
SUSE Linux Enterprise Module for Server Applications 15
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15
https://www.suse.com/security/cve/CVE-2018-16843.html
https://www.suse.com/security/cve/CVE-2018-16844.html
https://www.suse.com/security/cve/CVE-2018-16845.html
https://bugzilla.suse.com/1115015
https://bugzilla.suse.com/1115022
https://bugzilla.suse.com/1115025
Get the latest Linux and open source security news straight to your inbox.