Bug 2141496 (CVE-2022-41742) - CVE-2022-41742 nginx: Memory disclosure in the ngx_http_mp4_module
Summary: CVE-2022-41742 nginx: Memory disclosure in the ngx_http_mp4_module
Keywords:
Status: NEW
Alias: CVE-2022-41742
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Nobody
QA Contact:
URL:
Whiteboard:
Depends On: 2148866 2141497 2141498 2141499 2141500 2141501 2141502 2141503 2141504 2141505 2141513 2141515
Blocks: 2136367
TreeView+ depends on / blocked
 
Reported: 2022-11-10 04:53 UTC by Sandipan Roy
Modified: 2024-02-01 03:42 UTC (History)
33 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A vulnerability was found in NGINX’s module, ngx_http_mp4_module. This flaw allows a local attacker to cause a worker process crash or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products built with ngx_http_mp4_module when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger the processing of a specially crafted audio or video file with ngx_http_mp4_module.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2022-11-10 04:53:41 UTC
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a specially crafted audio or video file. The issue affects only NGINX products that are built with the module ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.

https://nginx.org/en/security_advisories.html

Comment 1 Sandipan Roy 2022-11-10 04:58:33 UTC
Created nginx tracking bugs for this issue:

Affects: epel-all [bug 2141498]
Affects: fedora-all [bug 2141500]


Created nginx:1.20/nginx tracking bugs for this issue:

Affects: fedora-all [bug 2141501]


Created nginx:mainline/nginx tracking bugs for this issue:

Affects: epel-all [bug 2141499]
Affects: fedora-all [bug 2141502]


Note You need to log in before you can comment on or make changes to this bug.