Lucene search

K
mageiaGentoo FoundationMGASA-2022-0398
HistoryOct 28, 2022 - 9:54 a.m.

Updated nginx packages fix security vulnerability

2022-10-2809:54:08
Gentoo Foundation
advisories.mageia.org
23
nginx
packages
security
vulnerability
ngx_http_mp4_module
attacker
worker process
crash
memory disclosure
mp4 file
cve-2022-41741
cve-2022-41742
unix

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%

Two security issues were identified in the ngx_http_mp4_module, which might allow an attacker to cause a worker process crash or worker process memory disclosure by using a specially crafted mp4 file, or might have potential other impact. (CVE-2022-41741, CVE-2022-41742)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchnginx< 1.18.0-5.3nginx-1.18.0-5.3.mga8

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

5.1%