6.1
CVSSv3

CVE-2018-16845

Published: 07/11/2018 Updated: 22/02/2022
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 4.2 | Exploitability Score: 1.8
VMScore: 518
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

nginx prior to 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an malicious user to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

f5 nginx

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

opensuse leap 15.1

apple xcode

Vendor Advisories

Debian Bug report logs - #913090 nginx: CVE-2018-16843 CVE-2018-16844 CVE-2018-16845 Package: src:nginx; Maintainer for src:nginx is Debian Nginx Maintainers <pkg-nginx-maintainers@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 6 Nov 2018 20:27:01 UTC Severity: grave Tags: ...
Several security issues were fixed in nginx ...
Synopsis Important: rh-nginx18-nginx security update Type/Severity Security Advisory: Important Topic An update for rh-nginx18-nginx is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Syste ...
Synopsis Important: rh-nginx114-nginx security update Type/Severity Security Advisory: Important Topic An update for rh-nginx114-nginx is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Sys ...
Synopsis Important: rh-nginx112-nginx security update Type/Severity Security Advisory: Important Topic An update for rh-nginx112-nginx is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Sys ...
Synopsis Important: rh-nginx110-nginx security update Type/Severity Security Advisory: Important Topic An update for rh-nginx110-nginx is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Sys ...
An instance of missing input sanitization was found in the mp4 module for nginx A local attacker could create a specially crafted video file that, when streamed by the server, would cause a denial of service (server crash or hang) and, possibly, information disclosure ...

Github Repositories

blog

title tags category date 本博客更新日志 Nginx Blog Blog 2018-01-10 2020-522 更新 我住的地方nas就在我旁边,一个单间。晚上有点吵,又想晚上反正也不用,挂了四块硬盘的nas,http 服务也挂在上面,基本是不会休眠的。 又想了下电费,觉得入手一个树莓派势

Управление пакетами Дистрибьюция софта Задание: Собрать собственный rpm пакет и разместить его в собственном репозитории Выполнение: Собираем nginx 1233 c поддержкой tls v13 (openssl-111q - 2022-Oct-12)

Домашнее задание Размещаем свой RPM в своем репозитории создать свой RPM; создать свой репо и разместить там свой RPM; реализовать это все либо в вагранте Решение Создан Vagrantfile с описанием машины с 8Гб RAM и 4 ядр

Размещаем свой RPM в своем репозитории Описание домашннего задания Создать свой RPM пакет (можно взять свое приложение, либо собрать, например, апач с определенными опциями) Создать свой репозиторий и размести

Выполнение домашних работ по курсу OTUS - Administrator LinuxProfessional Lesson1 Задача: 1) Обновить ядро ОС из репозитория ELRepo 2) Создать Vagrant box c помощью Packer 3) Загрузить Vagrant box в Vagrant Cloud Создаем ВМ используя и запуская Vagrantfile: # О