CVE-2018-16845
Summary
| CVE | CVE-2018-16845 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-07 14:29:00 UTC |
| Updated | 2022-02-22 19:27:00 UTC |
| Description | nginx before versions 1.15.6, 1.14.1 has a vulnerability in the ngx_http_mp4_module, which might allow an attacker to cause infinite loop in a worker process, cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted mp4 file. The issue only affects nginx if it is built with the ngx_http_mp4_module (the module is not built by default) and the .mp4. directive is used in the configuration file. Further, the attack is only possible if an attacker is able to trigger processing of a specially crafted mp4 file with the ngx_http_mp4_module. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Full Disclosure: APPLE-SA-2021-09-20-4 Xcode 13 |
FULLDISC |
seclists.org |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
Third Party Advisory |
| [SECURITY] [DLA 1572-1] nginx security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2120-1: important: Security update |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| About the security content of Xcode 13 - Apple Support |
CONFIRM |
support.apple.com |
|
| USN-3812-1: nginx vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Patch, Third Party Advisory |
| nginx MP4 Processing Bug Lets Remote Users Deny Service and Disclose Potentially Sensitive Information - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Debian -- Security Information -- DSA-4335-1 nginx |
DEBIAN |
www.debian.org |
Third Party Advisory |
| [nginx-announce] nginx security advisory (CVE-2018-16845) |
MISC |
mailman.nginx.org |
Mailing List, Patch, Vendor Advisory |
| nginx Multiple Denial of Service Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| 1644508 – (CVE-2018-16845) CVE-2018-16845 nginx: Denial of service and memory disclosure via mp4 module |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 375873 Apple Xcode Prior to 13 Vulnerability (HT212818)
- 500426 Alpine Linux Security Update for nginx
- 504185 Alpine Linux Security Update for nginx
- 730358 Nginx Denial of Service (DoS) Vulnerability