Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2018.0459
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2018-0459)
Summary:The remote host is missing an update for the 'nginx' package(s) announced via the MGASA-2018-0459 advisory.
Description:Summary:
The remote host is missing an update for the 'nginx' package(s) announced via the MGASA-2018-0459 advisory.

Vulnerability Insight:
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the
implementation of HTTP/2 that can allow for excessive memory consumption
(CVE-2018-16843).

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the
implementation of HTTP/2 that can allow for excessive CPU usage
(CVE-2018-16844).

nginx before versions 1.15.6, 1.14.1 has a vulnerability in the
ngx_http_mp4_module, which might allow an attacker to cause infinite
loop in a worker process, cause a worker process crash, or might result
in worker process memory disclosure by using a specially crafted mp4
file (CVE-2018-16845).

Affected Software/OS:
'nginx' package(s) on Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-16843
BugTraq ID: 105868
http://www.securityfocus.com/bid/105868
Debian Security Information: DSA-4335 (Google Search)
https://www.debian.org/security/2018/dsa-4335
http://seclists.org/fulldisclosure/2021/Sep/36
http://mailman.nginx.org/pipermail/nginx-announce/2018/000220.html
RedHat Security Advisories: RHSA-2018:3653
https://access.redhat.com/errata/RHSA-2018:3653
RedHat Security Advisories: RHSA-2018:3680
https://access.redhat.com/errata/RHSA-2018:3680
RedHat Security Advisories: RHSA-2018:3681
https://access.redhat.com/errata/RHSA-2018:3681
http://www.securitytracker.com/id/1042038
SuSE Security Announcement: openSUSE-SU-2019:2120 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.html
https://usn.ubuntu.com/3812-1/
Common Vulnerability Exposure (CVE) ID: CVE-2018-16844
Common Vulnerability Exposure (CVE) ID: CVE-2018-16845
http://mailman.nginx.org/pipermail/nginx-announce/2018/000221.html
https://lists.debian.org/debian-lts-announce/2018/11/msg00010.html
RedHat Security Advisories: RHSA-2018:3652
https://access.redhat.com/errata/RHSA-2018:3652
http://www.securitytracker.com/id/1042039
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.