nginx is vulnerable to denial of service. The vulnerability exists due to a memory corruption in ngx_http_mp4_module
when the mp4 directive is used in the configuration file which allows an attacker to cause an application crash using a specially crafted audio or video file.
github.com/advisories/GHSA-3v5h-538g-pr7g
lists.debian.org/debian-lts-announce/2022/11/msg00031.html
lists.fedoraproject.org/archives/list/[email protected]/message/BPRVYA4FS34VWB4FEFYNAD7Z2LFCJVEI/
lists.fedoraproject.org/archives/list/[email protected]/message/FD6M3PVVKO35WLAA7GLDBS6TEQ26SM64/
lists.fedoraproject.org/archives/list/[email protected]/message/WBORRVG7VVXYOAIAD64ZHES2U2VIUKFQ/
secdb.alpinelinux.org/edge/main.yaml
secdb.alpinelinux.org/v3.16/main.yaml
security.netapp.com/advisory/ntap-20230120-0005/
support.f5.com/csp/article/K81926432
www.debian.org/security/2022/dsa-5281