Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Ubuntu 14.04: USN-7014-3 critical: nginx denial of service

ubuntu
Calendar Grey October 14, 2024
Dist Ubuntu Esm H88
An essential nginx upgrade for Ubuntu 14.04 addresses vulnerabilities linked to incorrect network data that could lead to system failures.
nginx could be made to crash if it received specially crafted network traffic.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: nginx could be made to crash if it received specially crafted network traffic. Software Description: - nginx: small, powerful, scalable web/proxy server Details: USN-7014-1 fixed a vulnerability in nginx. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details:   It was discovered that the nginx ngx_http_mp4 module incorrectly handled   certain malformed mp4 files. In environments where the mp4 directive is in   use, a remote attacker could possibly use this issue to cause nginx to   crash, resulting in a denial of service.

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS    nginx                           1.4.6-1ubuntu3.9+esm5                                    Available with Ubuntu Pro    nginx-common                    1.4.6-1ubuntu3.9+esm5                                    Available with Ubuntu Pro    nginx-core                      1.4.6-1ubuntu3.9+esm5                                    Available with Ubuntu Pro    nginx-extras                    1.4.6-1ubuntu3.9+esm5                                    Available with Ubuntu Pro    nginx-full                      1.4.6-1ubuntu3.9+esm5                                    Available with Ubuntu Pro    nginx-light                     1.4.6-1ubuntu3.9+esm5                                    Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

References

   https://ubuntu.com/security/notices/USN-7014-3

   https://ubuntu.com/security/notices/USN-7014-2

   https://ubuntu.com/security/notices/USN-7014-1

   CVE-2024-7347

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7014-3

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here